[Full-Disclosure] [SECURITY] [DSA-403-1] userland can access Linux kernel memory

Florian Weimer fw at deneb.enyo.de
Tue Dec 2 16:43:09 GMT 2003


Wojciech Purczynski wrote:

> This is not an integer overflow bug. do_brk() doesn't verify its arguments
> at all, allowing to create arbitrarily large virtual memory mapping (vma)
> consuming kernel memory.

At least this explains why it wasn't found by the Stanford checker tool.
Thanks.




Full-Disclosure is hosted and sponsored by Secunia.