Re: [PATCH] splice: fix user pointer access in get_iovec_page_array()

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Bastian Blank <bastian@...>, Pekka J Enberg <penberg@...>, <torvalds@...>, <linux-kernel@...>, <stable@...>, <jens.axboe@...>, <akpm@...>, <ndenev@...>, <oliver.pntr@...>
Date: Sunday, February 10, 2008 - 11:31 am

Signed-off-by: Oliver Pinter <oliver.pntr@gmail.com>

----8<----

Linux pancs 2.6.22.17-opt2-cve2 #1 SMP Sun Feb 10 16:22:37 CET 2008
i686 GNU/Linux
-----------------------------------
 Linux vmsplice Local Root Exploit
 By qaaz
-----------------------------------
[+] mmap: 0x0 .. 0x1000
[+] page: 0x0
[+] page: 0x20
[+] mmap: 0x4000 .. 0x5000
[+] page: 0x4000
[+] page: 0x4020
[+] mmap: 0x1000 .. 0x2000
[+] page: 0x1000
[+] mmap: 0xb7f2d000 .. 0xb7f5f000
[-] vmsplice: Bad address

-----

oliver@pancs:/tmp$ uname -a && ./2623_2624_root_exploit
Linux pancs 2.6.22.17-opt2-cve2 #1 SMP Sun Feb 10 16:22:37 CET 2008
i686 GNU/Linux
-----------------------------------
 Linux vmsplice Local Root Exploit
 By qaaz
-----------------------------------
[+] addr: 0xc01112e9
[-] wtf


---->8----
On 2/10/08, Bastian Blank <bastian@waldi.eu.org> wrote:


-- 
Thanks,
Oliver
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] splice: fix user pointer access in get_iovec_pag..., Oliver Pinter, (Sun Feb 10, 11:31 am)