oss-sec mailing list archives
Re: kernel: uio: CVE-2013-6763 [was: Re: [oss-security] some unstracked linux kernel security fixes]
From: Linus Torvalds <torvalds () linux-foundation org>
Date: Mon, 2 Dec 2013 19:44:53 -0800
On Mon, Dec 2, 2013 at 7:40 PM, Greg Kroah-Hartman <gregkh () linuxfoundation org> wrote:
On Tue, Nov 26, 2013 at 01:18:39PM +0100, Petr Matousek wrote:IOW, with the current changes, isn't the functionality broken for non page-aligned addr and/or size?This should now be fixed in Linus's tree, right?
Well, that depends on what you mean by "fixed". If somebody depended on "we'll just mmap the page(s) that contained the partial and unaligned resource", then current git is very very broken, because it doesn't allow that at all. But if you meant that somebody could mess with things and try to access crud *around* a non-page-aligned resource, then current git fixed that and no longer allows mmap's that expose other resources aside from the one explicitly managed by uio. Linus
Current thread:
- some unstracked linux kernel security fixes Nico Golde (Nov 03)
- Re: some unstracked linux kernel security fixes Kurt Seifried (Nov 04)
- Re: some unstracked linux kernel security fixes Petr Matousek (Nov 12)
- Re: some unstracked linux kernel security fixes Petr Matousek (Nov 14)
- Re: some unstracked linux kernel security fixes Dan Carpenter (Nov 14)
- Re: some unstracked linux kernel security fixes Petr Matousek (Nov 14)
- kernel: uio: CVE-2013-6763 [was: Re: [oss-security] some unstracked linux kernel security fixes] Petr Matousek (Nov 26)
- Re: kernel: uio: CVE-2013-6763 [was: Re: [oss-security] some unstracked linux kernel security fixes] Greg Kroah-Hartman (Dec 02)
- Re: kernel: uio: CVE-2013-6763 [was: Re: [oss-security] some unstracked linux kernel security fixes] Linus Torvalds (Dec 02)
- Re: kernel: uio: CVE-2013-6763 [was: Re: [oss-security] some unstracked linux kernel security fixes] Petr Matousek (Dec 04)
- Re: some unstracked linux kernel security fixes Petr Matousek (Nov 14)