Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110228203255.GA4669@outflux.net>
Date: Mon, 28 Feb 2011 12:32:55 -0800
From: Kees Cook <kees@...ntu.com>
To: oss-security@...ts.openwall.com
Subject: CVE request: kernel: OOM-killer via argv expansion

Hi,

I think the flaw[1] with argv-expansion triggering the OOM-killer
incorrectly needs its own CVE.

While the stack guard page and the fixes[2] for CVE-2010-3858 certainly
improved things, argv expansion can still be tricked into OOM-killing the
entire system. Solutions were discussed on the original thread, but
were not finished. Recently a set of patches[3] has been re-proposed to fix
this issue. Regardless, it should probably get its own CVE assigned.

Thanks,

-Kees

[1] https://lkml.org/lkml/2010/8/27/429
[2] http://git.kernel.org/linus/1b528181b2ffa14721fb28ad1bd539fe1732c583
[3] https://lkml.org/lkml/2011/2/25/227

-- 
Kees Cook
Ubuntu Security Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.