oss-sec mailing list archives

Re: CVE Request -- kernel: futex: clear robust_list on execve


From: Solar Designer <solar () openwall com>
Date: Thu, 10 May 2012 04:27:39 +0400

Petr -

On Wed, May 09, 2012 at 09:30:55PM +0200, Petr Matousek wrote:
In this case single-threaded (privileged) Xorg was run with a stale
robust list pointer that accidentally fell into MMIO area

Wow.  Thank you for your helpful answers, and for including that info on
the RH Bugzilla entry.

So this gives us another attack scenario: not only on multi-threaded
programs, but also on programs that have MMIO or e.g. disk files mmap'ed
and writable.

Alexander


Current thread: