oss-sec mailing list archives

Re: Our learnings from 42 Linux kernel exploits, we are limiting io_uring


From: Solar Designer <solar () openwall com>
Date: Tue, 25 Jul 2023 16:09:04 +0200

On Tue, Jul 25, 2023 at 02:31:55PM +0200, Marcus Meissner wrote:
https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html

has been updated with exploit information.

I tried to backtrack through kernel git to find the exact commit where
this locking problem got fixed, but I gave up after a while after multiple
refactoring (and a filemove) in the io_uring codel.

I guess it's this:

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.15.y&id=fb348857e7b67eefe365052f1423427b66dedbf3

as mentioned in:

https://twitter.com/VAR10CK/status/1683303642173153280

Alexander


Current thread: