Re: mmap_min_addr and your local LSM (ok, just SELinux)

From: Arjan van de Ven
Date: Mon Jul 20 2009 - 23:47:44 EST


On Mon, 20 Jul 2009 19:23:43 -0400
Eric Paris <eparis@xxxxxxxxxx> wrote:
>
> Does anyone see a better way to let users continue to be users while
> protecting most people? Yes SELinux is stronger in some areas than
> without confining the ability to map the 0 page, but as has be rightly
> pointed out it's foolish an broken that SELinux can weaken any
> protections.

one option is to allow the page to be mapped, but only as
non-executable... in DOS that memory isn't where code lives anyway...


--
Arjan van de Ven Intel Open Source Technology Centre
For development, discussion and tips for power savings,
visit http://www.lesswatts.org
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/