mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* copy_from_user
@ 2003-06-18  6:50 Paul Mackerras
  2003-06-18  7:31 ` copy_from_user Andrew Morton
  0 siblings, 1 reply; 3+ messages in thread
From: Paul Mackerras @ 2003-06-18  6:50 UTC (permalink / raw)
  To: torvalds, akpm; +Cc: linux-kernel

Some time ago (in the 2.1 series IIRC) we added code to copy_from_user
to zero the remainder of the destination buffer if we faulted on the
source.  The motive was to eliminate some potential security holes
that could arise if callers didn't check the return value from
copy_from_user and continued on to pass the contents of the
destination buffer back to userspace in one way or another.

However, I notice that copy_from_user on i386 in 2.5 doesn't clear the
destination if the access_ok() check fails, or if the size is 1, 2 or
4.  Have all the callers of copy_from_user been checked?  Is the
zeroing of the destination no longer necessary?

Thanks,
Paul.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-06-18 12:13 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-06-18  6:50 copy_from_user Paul Mackerras
2003-06-18  7:31 ` copy_from_user Andrew Morton
2003-06-18 12:26   ` copy_from_user Paul Mackerras

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®