All of lore.kernel.org
 help / color / mirror / Atom feed
From: Al Viro <viro@ftp.linux.org.uk>
To: Jon Smirl <jonsmirl@gmail.com>
Cc: gregkh@suse.de, linux-kernel@vger.kernel.org, stable@kernel.org
Subject: Re: [patch 03/26] sysfs: zero terminate sysfs write buffers (CVE-2006-1055)
Date: Wed, 5 Apr 2006 16:39:57 +0100	[thread overview]
Message-ID: <20060405153957.GI27946@ftp.linux.org.uk> (raw)
In-Reply-To: <9e4733910604050838g339d48cao4e0f8582f6d90187@mail.gmail.com>

On Wed, Apr 05, 2006 at 11:38:06AM -0400, Jon Smirl wrote:
> On 4/5/06, Al Viro <viro@ftp.linux.org.uk> wrote:
> > On Wed, Apr 05, 2006 at 07:09:28PM +0400, Sergey Vlasov wrote:
> > > This will break the "color_map" sysfs file for framebuffers -
> > > drivers/video/fbsysfs.c:store_cmap() expects to get exactly 4096 bytes
> > > for a colormap with 256 entries.  In fact, the original patch which
> > > changed PAGE_SIZE - 1 to PAGE_SIZE:
> >
> > ... cheerfully assuming that nobody assumes NUL-termination and
> > everyone (sysfs patch writers!) certainly uses the length argument.
> > Fscking brilliant, that.
> >
> > Are you willing to audit all sysfs ->show() in the kernel?  Original
> > author of that turd had not been.
> >
> > FWIW, "color_map" is a blatant abuse of interface.  Doesn't get
> > any more borderline...
> 
> The firmware interface is worse. You write the ROM image line by line
> to the attribute and a hidden counter tracks how far your are into the
> image.
> 
> There needs to be a standardized way to transfer larger pieces of data
> via sysfs or we should go back to IOCTLs.

How about _NOT_ using sysfs and just having ->read()/->write() on a file in fs
of your own?  ~20 lines for all of it, not counting #include...

  reply	other threads:[~2006-04-05 15:40 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20060404235634.696852000@quad.kroah.org>
2006-04-04 23:59 ` [patch 00/26] 2.6.16.2 -stable review gregkh
2006-04-04 23:59   ` [patch 01/26] tlclk: fix handling of device major gregkh
2006-04-04 23:59   ` [patch 02/26] USB: Fix irda-usb use after use gregkh
2006-04-05  0:16     ` David S. Miller
2006-04-06  0:55       ` [stable] " Greg KH
2006-04-05  0:22     ` Randy.Dunlap
2006-04-04 23:59   ` [patch 03/26] sysfs: zero terminate sysfs write buffers (CVE-2006-1055) gregkh
2006-04-05 15:09     ` Sergey Vlasov
2006-04-05 15:21       ` Al Viro
2006-04-05 15:38         ` Jon Smirl
2006-04-05 15:39           ` Al Viro [this message]
2006-04-05 15:43             ` Jon Smirl
2006-04-05 15:46               ` Al Viro
2006-04-05 16:18                 ` Jon Smirl
2006-04-05 17:04                   ` Al Viro
2006-04-05 19:58             ` Valdis.Kletnieks
2006-04-05 20:07               ` Greg KH
2006-04-06  1:05               ` Al Viro
2006-04-05 16:34         ` Jon Smirl
2006-04-05 17:02           ` Al Viro
2006-04-05 17:06             ` Jon Smirl
2006-04-05 17:27               ` Al Viro
2006-04-05 15:30       ` Jon Smirl
2006-04-05 18:52         ` [stable] " Greg KH
2006-04-04 23:59   ` [patch 04/26] USB: EHCI full speed ISO bugfixes gregkh
2006-04-04 23:59   ` [patch 05/26] USB: usbcore: usb_set_configuration oops (NULL ptr dereference) gregkh
2006-04-05  0:00   ` [patch 06/26] sbp2: fix spinlock recursion gregkh
2006-04-05  0:00   ` [patch 07/26] powerpc: make ISA floppies work again gregkh
2006-04-05  0:00   ` [patch 08/26] PCMCIA_SPECTRUM must select FW_LOADER gregkh
2006-04-05  0:00   ` [patch 09/26] pcmcia: permit single-character-identifiers gregkh
2006-04-05  0:00   ` [patch 10/26] opti9x - Fix compile without CONFIG_PNP gregkh
2006-04-05  0:00   ` [patch 11/26] IPOB: Move destructor from neigh->ops to neigh_param gregkh
2006-04-05  0:07     ` David S. Miller
2006-04-05  0:12       ` [stable] " Greg KH
2006-04-05  0:14       ` Roland Dreier
2006-04-05  0:17         ` David S. Miller
2006-04-05  0:42           ` Roland Dreier
2006-04-05  0:47             ` David S. Miller
2006-04-05  1:08               ` Roland Dreier
2006-04-05  7:58               ` Michael S. Tsirkin
2006-04-05  0:00   ` [patch 12/26] Mark longhaul driver as broken gregkh
2006-04-05  0:00   ` [patch 13/26] isicom must select FW_LOADER gregkh
2006-04-05  0:00   ` [patch 14/26] {ip, nf}_conntrack_netlink: fix expectation notifier unregistration gregkh
2006-04-05  0:00   ` [patch 15/26] wrong error path in dup_fd() leading to oopses in RCU gregkh
2006-04-05  0:00   ` [patch 16/26] Fix the p4-clockmod N60 errata workaround gregkh
2006-04-05  0:00   ` [patch 17/26] Fix module refcount leak in __set_personality() gregkh
2006-04-05  0:00   ` [patch 18/26] fib_trie.c node freeing fix gregkh
2006-04-05  0:01   ` [patch 19/26] fbcon: Fix big-endian bogosity in slow_imageblit() gregkh
2006-04-05  0:01   ` [patch 20/26] drivers/net/wireless/ipw2200.c: fix an array overun gregkh
2006-04-05  0:01   ` [patch 21/26] Fix NULL pointer dereference in node_read_numastat() gregkh
2006-04-05  0:01   ` [patch 22/26] AIRO{,_CS} <-> CRYPTO fixes gregkh
2006-04-05  0:01   ` [patch 23/26] Add default entry for CTL Travel Master U553W gregkh
2006-04-05  0:01   ` [patch 24/26] hostap: Fix EAPOL frame encryption gregkh
2006-04-05  0:01   ` [patch 25/26] knfsd: Correct reserved reply space for read requests gregkh
2006-04-05  0:01   ` [patch 26/26] kdump proc vmcore size oveflow fix gregkh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060405153957.GI27946@ftp.linux.org.uk \
    --to=viro@ftp.linux.org.uk \
    --cc=gregkh@suse.de \
    --cc=jonsmirl@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.