Thread (13 messages) flat view 13 messages, 4 authors, 2007-05-03

Re: [PATCH 1/5] [NETLINK]: Fix use after free in netlink_recvmsg

From: Marcel Holtmann <marcel@holtmann.org>
Date: 2007-05-03 12:27:16
Also in: linux-fsdevel, lkml

Hi Dave,
quoted
When the user passes in MSG_TRUNC the skb is used after getting freed.

Signed-off-by: Patrick McHardy <redacted>
Signed-off-by: David Howells <dhowells@redhat.com>
Ugh, good catch, applied :-)
it seems this could be easily exploited and is at least a local DoS. It
should be a candidate for the -stable kernel.

Regards

Marcel

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help