Thread (20 messages) flat view 20 messages, 12 authors, 2016-08-25

Re: CVE-2014-9900 fix is not upstream

From: Lennart Sorensen <hidden>
Date: 2016-08-24 14:03:23
Also in: lkml

On Tue, Aug 23, 2016 at 10:25:45PM +0100, Al Viro wrote:
Sadly, sizeof is what we use when copying that sucker to userland.  So these
padding bits in the end would've leaked, true enough, and the case is somewhat
weaker.  And any normal architecture will have those, but then any such
architecture will have no more trouble zeroing a 32bit value than 16bit one.
Hmm, good point.  Too bad I don't see a compiler option of "zero all
padding in structs".  Certainly generating the code should not really
be that different.

I see someone did request it 2 years ago:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=63479

-- 
Len Sorensen
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help