Bugtraq mailing list archives
Hotfix for new mremap vulnerability
From: Pavel harry_x Palát <harry_x () babylon5 cz>
Date: Thu, 19 Feb 2004 17:32:30 +0100 (CET)
Greetings, Here (http://wizard.ath.cx/fixmremap2.tar.gz) is small hotfix for newly discovered mremap() vulnerability. It doesn't directly change do_mremap() code, it just overwrites syscall handler with LKM. In my opinion it is enough to fix just mremap() syscall because at least on x86 there are no other functions which would use do_mremap directly. But this may not be true on others platforms (for example ia64)... The package contains the hotfix and a small proof of concept program which can be used to see if kernel is vulnerable. Use at your own risk. Pavel Palát -- Pavel "harry_x" Palát harry_x () babylon5 cz irc: #mistral.cz on IRCnet The only way of finding the limits to the possible is by going beyond them to the impossible Arthur C. Clark
Current thread:
- Second critical mremap() bug found in all Linux kernels Paul Starzetz (Feb 18)
- Re: Second critical mremap() bug found in all Linux kernels Dan Yefimov (Feb 19)
- Re: Second critical mremap() bug found in all Linux kernels Jared M Breland (Feb 19)
- Hotfix for new mremap vulnerability Pavel harry_x Palát (Feb 20)
- Re: Hotfix for new mremap vulnerability Marc-Christian Petersen (Feb 23)
- <Possible follow-ups>
- Re: Second critical mremap() bug found in all Linux kernels Steve Bremer (Feb 18)
- RE: Second critical mremap() bug found in all Linux kernels tlarholm (Feb 19)