git: 769536bcb5c3 - releng/13.3 - ktrace: Fix an inverted privilege check

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Wed, 07 Aug 2024 13:44:59 UTC
The branch releng/13.3 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=769536bcb5c334ca551b4dc88cf7486bd960e192

commit 769536bcb5c334ca551b4dc88cf7486bd960e192
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2024-08-07 13:38:54 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2024-08-07 13:43:45 +0000

    ktrace: Fix an inverted privilege check
    
    Approved by:    so
    Security:       FreeBSD-SA-24:06.ktrace
    Security:       CVE-2024-6760
    Fixes:  1762f674ccb5 ("ktrace: pack all ktrace parameters into allocated structure ktr_io_params")
    
    (cherry picked from commit 166b7573b5220aadf8b02a85933c9651b909b309)
    (cherry picked from commit f702110bc4bcc593b38674ec6e4fadf6c4626432)
---
 sys/kern/kern_ktrace.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sys/kern/kern_ktrace.c b/sys/kern/kern_ktrace.c
index 2729d0880b31..cc51dbae46f7 100644
--- a/sys/kern/kern_ktrace.c
+++ b/sys/kern/kern_ktrace.c
@@ -585,7 +585,7 @@ ktrprocexec(struct proc *p)
 	PROC_LOCK_ASSERT(p, MA_OWNED);
 
 	kiop = p->p_ktrioparms;
-	if (kiop == NULL || priv_check_cred(kiop->cr, PRIV_DEBUG_DIFFCRED))
+	if (kiop == NULL || priv_check_cred(kiop->cr, PRIV_DEBUG_DIFFCRED) == 0)
 		return (NULL);
 
 	mtx_lock(&ktrace_mtx);