[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <1368834517.3301.130.camel@edumazet-glaptop>
Date: Fri, 17 May 2013 16:48:37 -0700
From: Eric Dumazet <eric.dumazet@...il.com>
To: Joe Perches <joe@...ches.com>
Cc: David Miller <davem@...emloft.net>,
netdev <netdev@...r.kernel.org>,
Daniel Borkmann <dborkman@...hat.com>
Subject: Re: [PATCH net-next] filter: do not output bpf image address for
security reason
On Fri, 2013-05-17 at 16:42 -0700, Joe Perches wrote:
> Are stable equivalents for versions before commit 79617801ea0
> necessary?
>
I do not think so.
In order to get these messages printed, the admin had to specifically do
echo 2 >/proc/sys/net/core/bpf_jit_enable
And quite frankly I doubt anybody would need to do such thing, but
netdev guys writing/patching BPF JIT
And even with these messages printed, you need some bug in the kernel
allowing an exploit.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists