Thread (10 messages) flat view 10 messages, 6 authors, 2007-07-07

Re: Executing from readablee, no-exec pages

From: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Date: 2007-07-07 02:33:42

Well, it means that leaving VM_READ out of the check (except where the
hardware PTE has an exec bit) isn't really buying us anything
security-wise (especially since the primary reason for no-exec protection
is to avoid code injections via stack overflow, and those pages will
usually already be present), so it doesn't hurt much to let things keep
working.

At the least, I'd like it to keep working for a few more kernel releases
(with a warning printed when a VM_EXEC-only test would have failed), so
people have time to upgrade glibc.
I agree. Care to send a patch ? :-0

Ben.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help