Andrew Morton wrote:
> Adrian Cox wrote:
>>Can this actually be exploited? I assume the test on __copy_from_user()
>>is there in case another thread changes memory mappings while
>>generic_file_write() is running. My attempts to do this haven't yet
>>succeeded.
> I'd expect it to occur if you simply pass an unmapped address
> to write()?
No, because the first thing generic_file_write does is an access_ok()
check. It can only happen if the permissions change during the function.
That's why it's hard to exploit for real.
-- Adrian Cox http://www.humboldt.co.uk/- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
This archive was generated by hypermail 2b29 : Thu Aug 23 2001 - 21:00:50 EST