Files
Linux/net
Al Viro 8920e8f94c [PATCH] Fix 32bit sendmsg() flaw
When we copy 32bit ->msg_control contents to kernel, we walk the same
userland data twice without sanity checks on the second pass.

Second version of this patch: the original broke with 64-bit arches
running 32-bit-compat-mode executables doing sendmsg() syscalls with
unaligned CMSG data areas

Another thing is that we use kmalloc() to allocate and sock_kfree_s()
to free afterwards; less serious, but also needs fixing.

Signed-off-by: Al Viro <[email protected]>
Signed-off-by: David Woodhouse <[email protected]>
Signed-off-by: Chris Wright <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
2005-09-08 08:14:11 -07:00
..
2005-08-29 15:32:25 -07:00
2005-09-06 15:49:39 -07:00
2005-08-29 16:01:32 -07:00
2005-08-29 16:01:32 -07:00
2005-09-05 18:08:11 -07:00
…
2005-08-29 15:31:14 -07:00
2005-09-06 15:49:39 -07:00
2005-09-06 15:49:39 -07:00
2005-08-29 16:01:32 -07:00
2005-09-08 08:14:11 -07:00
2005-09-01 18:02:01 -04:00
…
2005-09-08 08:14:11 -07:00
2005-08-29 16:01:32 -07:00
…