* Re: CVE-2022-49444: module: fix [e_shstrndx].sh_size=0 OOB access
[not found] <2025022658-CVE-2022-49444-ff21@gregkh>
@ 2025-03-17 8:14 ` Brendan Jackman
2025-03-17 13:46 ` Greg KH
0 siblings, 1 reply; 2+ messages in thread
From: Brendan Jackman @ 2025-03-17 8:14 UTC (permalink / raw)
To: gregkh; +Cc: cve, linux-cve-announce, linux-kernel
> It is trivial to craft a module to trigger OOB access in this line:
Requires loading a crafted module? I don't think there's any coherent threat
model where this is a vuln. Probably a CVE to revoke?
Unless there's some detail I'm not aware of, e.g. this bit of the module isn't
signed or something.
Cheers,
Brendan
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CVE-2022-49444: module: fix [e_shstrndx].sh_size=0 OOB access
2025-03-17 8:14 ` CVE-2022-49444: module: fix [e_shstrndx].sh_size=0 OOB access Brendan Jackman
@ 2025-03-17 13:46 ` Greg KH
0 siblings, 0 replies; 2+ messages in thread
From: Greg KH @ 2025-03-17 13:46 UTC (permalink / raw)
To: Brendan Jackman; +Cc: cve, linux-cve-announce, linux-kernel
On Mon, Mar 17, 2025 at 08:14:16AM +0000, Brendan Jackman wrote:
> > It is trivial to craft a module to trigger OOB access in this line:
>
> Requires loading a crafted module? I don't think there's any coherent threat
> model where this is a vuln. Probably a CVE to revoke?
Look at the commit this is marked as fixing. It was a "feature"
introduced to properly harden elf sections in modules. So if you are
relying on that new thing, then yes, this is a vulnerability. If your
system does not, then your system is not vulnerable to this issue.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-03-17 13:47 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <2025022658-CVE-2022-49444-ff21@gregkh>
2025-03-17 8:14 ` CVE-2022-49444: module: fix [e_shstrndx].sh_size=0 OOB access Brendan Jackman
2025-03-17 13:46 ` Greg KH
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®