* CAN-2003-0018 vs 2.6?
@ 2004-03-29 13:15 Christoph Hellwig
2004-03-29 18:50 ` Andrew Morton
0 siblings, 1 reply; 2+ messages in thread
From: Christoph Hellwig @ 2004-03-29 13:15 UTC (permalink / raw)
To: akpm; +Cc: linux-kernel
CAN-2003-0018 (Linux O_DIRECT Direct Input/Output Information Leak
Vulnerability) is still not fixed in mainline 2.6.
Last time I pinged you you said you didn't like the fixes but we're
getting to the point where 2.6 gets seriously used and we should start
to care. In fact SuSE has been adding the patches to their tree now
which means an direct I/O API change which is kinda messy to maintain
for XFS (which isn't even affected by the vulnerability due to it's own
locking) that's supposed to supply vendors with uptodas.
So any plans to gets this in?
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CAN-2003-0018 vs 2.6?
2004-03-29 13:15 CAN-2003-0018 vs 2.6? Christoph Hellwig
@ 2004-03-29 18:50 ` Andrew Morton
0 siblings, 0 replies; 2+ messages in thread
From: Andrew Morton @ 2004-03-29 18:50 UTC (permalink / raw)
To: Christoph Hellwig; +Cc: linux-kernel
Christoph Hellwig <hch@lst.de> wrote:
>
> CAN-2003-0018 (Linux O_DIRECT Direct Input/Output Information Leak
> Vulnerability) is still not fixed in mainline 2.6.
>
> Last time I pinged you you said you didn't like the fixes but we're
> getting to the point where 2.6 gets seriously used and we should start
> to care. In fact SuSE has been adding the patches to their tree now
> which means an direct I/O API change which is kinda messy to maintain
> for XFS (which isn't even affected by the vulnerability due to it's own
> locking) that's supposed to supply vendors with uptodas.
>
> So any plans to gets this in?
The fixes for this have been ready to go for a week or so. It's 2.6.6-pre
material.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2004-03-29 18:50 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-29 13:15 CAN-2003-0018 vs 2.6? Christoph Hellwig
2004-03-29 18:50 ` Andrew Morton
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox