login
Header Space

 
 

[PATCH] vmsplice exploit fix (was: splice: fix user pointer access in get_iovec_page_array)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Pekka J Enberg <penberg@...>
Cc: <torvalds@...>, <linux-kernel@...>, <stable@...>, <jens.axboe@...>, <akpm@...>, <bastian@...>, <ndenev@...>, <oliver.pntr@...>
Date: Monday, February 11, 2008 - 3:29 am

Kudos to all involved in the rapid response.  But.

Information on patching this vulnerability is not available front and 
center in many of the places you would expect: kernel.org front page, 
debian.org front page, covered on planet.debian.org but without a 
pointer to the patch, and so on.  So this post provides a subject line 
for Google to find, and for good measure mentions the word 
vulnerability.

Also,

   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464953

I think many users would first go to kernel.org on a day like today, as 
I did.  Nothing to see there.  We could do a way better job of getting 
the word out.

Patch attached as posted above by Pekka.  For the mortals among us:

   cd linux-2.6.recent && patch <fix.vmsplice.exploit.patch -p1

Regards,

Daniel
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] vmsplice exploit fix (was: splice: fix user pointer ..., Daniel Phillips, (Mon Feb 11, 3:29 am)
speck-geostationary