oss-sec mailing list archives
Re: CVE Request -- kernel: futex: clear robust_list on execve
From: Solar Designer <solar () openwall com>
Date: Thu, 10 May 2012 04:27:39 +0400
Petr - On Wed, May 09, 2012 at 09:30:55PM +0200, Petr Matousek wrote:
In this case single-threaded (privileged) Xorg was run with a stale robust list pointer that accidentally fell into MMIO area
Wow. Thank you for your helpful answers, and for including that info on the RH Bugzilla entry. So this gives us another attack scenario: not only on multi-threaded programs, but also on programs that have MMIO or e.g. disk files mmap'ed and writable. Alexander
Current thread:
- Re: CVE Request -- kernel: futex: clear robust_list on execve Solar Designer (May 07)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Solar Designer (May 07)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Petr Matousek (May 09)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Solar Designer (May 09)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Petr Matousek (May 09)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Petr Matousek (May 09)
- Re: CVE Request -- kernel: futex: clear robust_list on execve Solar Designer (May 07)