Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 2 Apr 2019 19:51:32 +0200
From: Adam Zabrocki <pi3@....com.pl>
To: lkrg-users@...ts.openwall.com
Subject: Re: ON process[6291 | dockerd] has corrupted 'off' flag
 -> Trying to kill process[dockerd | 6291]!

Hi,

We didn't test docker scenario until now. I've just pushed some changes to the 
LKRG which should bring support for it.

Problem which you've seen is related to the OverlayFS internals. It looks like 
problem should be solved. At least that's the case from the tests which I've 
made. I would appreciate if more people can validate that as well ;-)

Thanks,
Adam

On Tue, Mar 26, 2019 at 09:53:05AM +0100, bryn1u85 wrote:
> Hey guys,
> 
> I have installed docker and run services, after that im getting some
> message in dmesg. It looks like LKRG is trying to kill docker process. It
> shoul be like that or it's false positive ?
> 
> 
> 
> [71053.959984] [p_lkrg] <Exploit Detection> ON process[6291 | dockerd] has
> > corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [71053.960051] [p_lkrg] <Exploit Detection> Trying to kill process[dockerd
> > | 6291]!
> > [71053.960447] [p_lkrg] <Exploit Detection> ON process[6291 | dockerd] has
> > corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [71053.960513] [p_lkrg] <Exploit Detection> Trying to kill process[dockerd
> > | 6291]!
> > [156062.762482] [p_lkrg] <Exploit Detection> ON process[31600 | dockerd]
> > has corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [156062.762537] [p_lkrg] <Exploit Detection> Trying to kill
> > process[dockerd | 31600]!
> > [156062.762703] [p_lkrg] <Exploit Detection> ON process[31600 | dockerd]
> > has corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [156062.762743] [p_lkrg] <Exploit Detection> Trying to kill
> > process[dockerd | 31600]!
> > [156069.458008] [p_lkrg] <Exploit Detection> ON process[11449 | dockerd]
> > has corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [156069.458051] [p_lkrg] <Exploit Detection> Trying to kill
> > process[dockerd | 11449]!
> > [156069.458246] [p_lkrg] <Exploit Detection> ON process[11449 | dockerd]
> > has corrupted 'off' flag => 0x29bbff7dee24682 (normalization via
> > 0x14ddffbef712341)!
> > [156069.458314] [p_lkrg] <Exploit Detection> Trying to kill
> > process[dockerd | 11449]!

-- 
pi3 (pi3ki31ny) - pi3 (at) itsec pl
http://pi3.com.pl

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.