mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] IPC DoS fix
@ 2013-11-02 21:26 Mathias Krause
  2013-11-02 21:26 ` [PATCH 1/2] ipc, msg: fix message length check for negative values Mathias Krause
  2013-11-02 21:26 ` [PATCH 2/2] ipc, msg: forbid negative values for "msgmax" Mathias Krause
  0 siblings, 2 replies; 8+ messages in thread
From: Mathias Krause @ 2013-11-02 21:26 UTC (permalink / raw)
  To: Linus Torvalds
  Cc: Andrew Morton, Davidlohr Bueso, Pax Team, Brad Spengler,
	linux-kernel, Mathias Krause

Hi Linus,

this series fixes a bug in the IPC code that allows root to instantly crash
the system. The first patch fixes the bug, the second one prevents msgmax
from getting negative in the first place. As that *might* break existing
userspace (for good?!) it's a separate patch.

The cc list is quite randomly choosen as there seem to be no maintainer for
ipc/. :/

Please apply!


Mathias Krause (2):
  ipc, msg: fix message length check for negative values
  ipc, msg: forbid negative values for "msgmax"

 ipc/ipc_sysctl.c |    6 +++---
 ipc/msg.c        |    2 +-
 2 files changed, 4 insertions(+), 4 deletions(-)

-- 
1.7.10.4


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2013-11-03 11:37 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-11-02 21:26 [PATCH 0/2] IPC DoS fix Mathias Krause
2013-11-02 21:26 ` [PATCH 1/2] ipc, msg: fix message length check for negative values Mathias Krause
2013-11-03  0:35   ` Linus Torvalds
2013-11-03  8:36     ` Mathias Krause
2013-11-03 11:36     ` [PATCHv2 0/2] IPC DoS fix Mathias Krause
2013-11-03 11:36       ` [PATCHv2 1/2] ipc, msg: fix message length check for negative values Mathias Krause
2013-11-03 11:36       ` [PATCHv2 2/2] ipc, msg: forbid negative values for "msg{max,mnb,mni}" Mathias Krause
2013-11-02 21:26 ` [PATCH 2/2] ipc, msg: forbid negative values for "msgmax" Mathias Krause

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®