From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Date: Fri, 3 Nov 2017 21:33:11 +0000 (UTC) From: Mathieu Desnoyers Message-ID: <2109876270.3592.1509744791959.JavaMail.zimbra@efficios.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Subject: [diamon-discuss] [RELEASE] LTTng-modules 2.9.6 and 2.10.3 (Linux kernel tracer) List-Id: DiaMon diagnostic and monitoring workgroup general discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: lttng-dev@lists.lttng.org, diamon-discuss@lists.linuxfoundation.org Hi, Versions 2.9.6 and 2.10.3 fix an input validation issue with the /proc/lttng-logger interface of lttng-modules. An ill-crafted input to the write system call to /proc/lttng-logger can trigger a kernel OOPS. Given that all users can write to that file, it means that arbitrary local users can trigger a kernel OOPS. It would be preferable to upgrade your lttng-modules to a version containing this fix. Thanks, Mathieu Project website: http://lttng.org Documentation: http://lttng.org/docs Download link: http://lttng.org/download Changelog: 2017-11-03 (National Sandwich Day) LTTng modules 2.9.6 * Fix: lttng-logger get_user_pages_fast error handling 2017-11-03 (National Sandwich Day) LTTng modules 2.10.3 * Fix: lttng-logger get_user_pages_fast error handling -- Mathieu Desnoyers EfficiOS Inc. http://www.efficios.com