lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:   Tue, 18 Sep 2018 09:54:47 +0300
From:   Dag Nygren <dag@...tech.fi>
To:     xen-devel@...ts.xenproject.org
Cc:     Boris Ostrovsky <boris.ostrovsky@...cle.com>,
        Jarkko Sakkinen <jarkko.sakkinen@...ux.intel.com>,
        jgross@...e.com, "Dr . Greg Wettstein" <greg@...ellic.com>,
        dunlapg@...ch.edu, linux-kernel@...r.kernel.org,
        stable@...r.kernel.org, jgg@...pe.ca,
        "Dr. Greg Wettstein" <greg@...d.enjellic.com>, peterhuewe@....de,
        linux-integrity@...r.kernel.org
Subject: Re: [Xen-devel] [PATCH v2] tpm: Restore functionality to xen vtpm driver.

On tisdag 18 september 2018 kl. 01:25:29 EEST Boris Ostrovsky wrote:
> On 9/17/18 5:19 PM, Jarkko Sakkinen wrote:

> > Just to understand this bug better why did not the wrong version
> > cause any undefined behavior? Sounds like a fatal bug. Does this
> > cause crashes?
> 
> AFAIK, no, no crashes. I haven't tested this myself (and I believe
> relatively few people use this functionality, which explains why this
> has not been fixed for so long) but I don't think it will necessarily
> crash. It's just that the frontend driver will be reading from wrong
> location, causing TPM not to function properly.

I bumped my head into this last week and spent most of the
week trying to figure out why the vtpm did not respond.
Finally found the email from the guy that dirscovered and fixed
it. Did the fix and rescompiled. Now it seems to be working
fine. The patch is surprisingly 2 years old!!
I will be very pleased to see it go in to the
official kernel!

But no crash. Just a timeout when trying to communicate with
the vtpm-engine.

Best
Dag



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ