All of lore.kernel.org
 help / color / mirror / Atom feed
From: Andres Salomon <dilinger@voxel.net>
To: linux-kernel@vger.kernel.org
Cc: akpm@osdl.org
Subject: Re: [PATCH] kernel_read result fixes
Date: Fri, 24 Dec 2004 18:36:36 -0500	[thread overview]
Message-ID: <1103931396.6224.6.camel@localhost> (raw)
In-Reply-To: <1103873064.5994.6.camel@localhost>

[-- Attachment #1: Type: text/plain, Size: 961 bytes --]

On Fri, 2004-12-24 at 02:24 -0500, Andres Salomon wrote:
> Hi,
> 
> A few potential vulnerabilities were pointed out by Katrina Tsipenyuk in
> <http://seclists.org/lists/linux-kernel/2004/Dec/1878.html>.  I haven't
> seen any discussion or fixes of the issue yet, so here's a patch
> (against 2.6.9).  The fixes are along the same lines as the previous
> binfmt_elf fixes.  There's one additional place (inside fs/binfmt_som.c)
> that a fix could be applied, but since that doesn't compile anyways, I
> didn't see a point in patching it.
> 
> 

Ok, you can ignore this; I believe the original advisory is bogus.
prepare_binprm ensures a 128 byte buffer that kernel_read data is copied
to; in case something smaller is copied in, the rest of the space is
zero'd out.  Thus, <128 reads are fine, and in many cases (as in
binfmt_script w/ tiny scripts less than 128 bytes in total) perfectly
valid.


-- 
Andres Salomon <dilinger@voxel.net>

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2004-12-24 23:36 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-12-24  7:24 [PATCH] kernel_read result fixes Andres Salomon
2004-12-24 23:36 ` Andres Salomon [this message]
2004-12-30  7:25 ` Andrew Morton
2004-12-30  7:46   ` Andres Salomon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1103931396.6224.6.camel@localhost \
    --to=dilinger@voxel.net \
    --cc=akpm@osdl.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.