lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Wed, 10 Nov 2010 06:53:43 +0100 From: Eric Dumazet <eric.dumazet@...il.com> To: David Miller <davem@...emloft.net> Cc: drosenberg@...curity.com, netdev@...r.kernel.org, stable@...nel.org, security@...nel.org Subject: Re: [PATCH] Prevent reading uninitialized memory with socket filters Le mardi 09 novembre 2010 à 21:28 -0800, David Miller a écrit : > From: Dan Rosenberg <drosenberg@...curity.com> > Date: Tue, 09 Nov 2010 17:28:44 -0500 > > > The "mem" array used as scratch space for socket filters is not > > initialized, allowing unprivileged users to leak kernel stack bytes. > > > > Signed-off-by: Dan Rosenberg <drosenberg@...curity.com> > > Prove it. And once done, add the checks in sk_chk_filter() ? Allow a load of mem[X] only if a prior store of mem[X] is proven. -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists