From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6BBA9C433F5 for ; Tue, 22 Mar 2022 23:18:40 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235062AbiCVXUG (ORCPT ); Tue, 22 Mar 2022 19:20:06 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:40192 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S236651AbiCVXUG (ORCPT ); Tue, 22 Mar 2022 19:20:06 -0400 Received: from mail105.syd.optusnet.com.au (mail105.syd.optusnet.com.au [211.29.132.249]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id ADA906541 for ; Tue, 22 Mar 2022 16:18:37 -0700 (PDT) Received: from dread.disaster.area (pa49-186-150-27.pa.vic.optusnet.com.au [49.186.150.27]) by mail105.syd.optusnet.com.au (Postfix) with ESMTPS id 8634110E4E74; Wed, 23 Mar 2022 10:18:36 +1100 (AEDT) Received: from dave by dread.disaster.area with local (Exim 4.92.3) (envelope-from ) id 1nWnlq-008h0W-FH; Wed, 23 Mar 2022 10:18:34 +1100 Date: Wed, 23 Mar 2022 10:18:34 +1100 From: Dave Chinner To: Zorro Lang Cc: fstests@vger.kernel.org, djwong@kernel.org Subject: Re: [PATCH v2 2/2] fstests: test dirty pipe vulnerability issue of CVE-2022-0847 Message-ID: <20220322231834.GG1609613@dread.disaster.area> References: <20220322182926.1829846-1-zlang@redhat.com> <20220322182926.1829846-3-zlang@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220322182926.1829846-3-zlang@redhat.com> X-Optus-CM-Score: 0 X-Optus-CM-Analysis: v=2.4 cv=deDjYVbe c=1 sm=1 tr=0 ts=623a594d a=sPqof0Mm7fxWrhYUF33ZaQ==:117 a=sPqof0Mm7fxWrhYUF33ZaQ==:17 a=kj9zAlcOel0A:10 a=o8Y5sQTvuykA:10 a=UgJECxHJAAAA:8 a=20KFwNOVAAAA:8 a=7-415B0cAAAA:8 a=3CX3X2KfUhofDhE1Ae0A:9 a=CjuIK1q_8ugA:10 a=-El7cUbtino8hM1DCn8D:22 a=biEYGPWJfzWAr4FL6Ov7:22 Precedence: bulk List-ID: X-Mailing-List: fstests@vger.kernel.org On Wed, Mar 23, 2022 at 02:29:26AM +0800, Zorro Lang wrote: > Test for the Dirty Pipe vulnerability (CVE-2022-0847) caused by an > uninitialized "pipe_buffer.flags" variable. The bug cause a file > can be overwritten even if a user/process is not permitted to write > it. It's fixed by 9d2231c5d74e ("lib/iov_iter: initialize "flags" in > new pipe_buffer"). > > Cc: Max Kellermann > Signed-off-by: Zorro Lang Looks good now! Reviewed-by: Dave Chinner -- Dave Chinner david@fromorbit.com