lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <309B89C4C689E141A5FF6A0C5FB2118B8C5F9877@ORSMSX101.amr.corp.intel.com>
Date:   Fri, 19 May 2017 21:12:58 +0000
From:   "Brown, Aaron F" <aaron.f.brown@...el.com>
To:     "Kirsher, Jeffrey T" <jeffrey.t.kirsher@...el.com>,
        David Miller <davem@...emloft.net>,
        "bpoirier@...e.com" <bpoirier@...e.com>
CC:     "s.priebe@...fihost.ag" <s.priebe@...fihost.ag>,
        "intel-wired-lan@...ts.osuosl.org" <intel-wired-lan@...ts.osuosl.org>,
        "netdev@...r.kernel.org" <netdev@...r.kernel.org>,
        "pmenzel@...gen.mpg.de" <pmenzel@...gen.mpg.de>,
        "Neftin, Sasha" <sasha.neftin@...el.com>,
        "stephen@...workplumber.org" <stephen@...workplumber.org>
Subject: RE: [PATCH v2] e1000e: Don't return uninitialized stats

> From: Kirsher, Jeffrey T
> Sent: Friday, May 19, 2017 1:17 AM
> To: David Miller <davem@...emloft.net>; bpoirier@...e.com
> Cc: s.priebe@...fihost.ag; intel-wired-lan@...ts.osuosl.org;
> netdev@...r.kernel.org; pmenzel@...gen.mpg.de; Neftin, Sasha
> <sasha.neftin@...el.com>; Brown, Aaron F <aaron.f.brown@...el.com>;
> stephen@...workplumber.org
> Subject: Re: [PATCH v2] e1000e: Don't return uninitialized stats
> 
> On Thu, 2017-05-18 at 10:46 -0400, David Miller wrote:
> > From: Benjamin Poirier <bpoirier@...e.com>
> > Date: Wed, 17 May 2017 16:24:13 -0400
> >
> > > Some statistics passed to ethtool are garbage because
> > > e1000e_get_stats64()
> > > doesn't write them, for example: tx_heartbeat_errors. This leaks kernel
> > > memory to userspace and confuses users.
> > >
> > > Do like ixgbe and use dev_get_stats() which first zeroes out
> > > rtnl_link_stats64.
> > >
> > > Fixes: 5944701df90d ("net: remove useless memset's in drivers
> > > get_stats64")
> > > Reported-by: Stefan Priebe <s.priebe@...fihost.ag>
> > > Signed-off-by: Benjamin Poirier <bpoirier@...e.com>

Tested-by: Aaron Brown <aaron.f.brown@...el.com>

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ