Re: [PATCH 3.19 091/123] gadgetfs: use-after-free in ->aio_read()

From: Alexander Holler
Date: Thu Mar 26 2015 - 06:22:49 EST


Am 25.03.2015 um 12:15 schrieb Alexander Holler:
Am 25.03.2015 um 12:08 schrieb Greg Kroah-Hartman:
On Wed, Mar 25, 2015 at 11:58:46AM +0100, Alexander Holler wrote:
As this has been broken since 3.16, and no one has taken the time to
fix
it since then, it's not really an issue here, people can just use
4.0 if
they want it.

Just a last comment: I've no idea if the bug might be exploitable. I haven't had a deeper look at what it fixes but in regard to memory problems I would prefer a careful solution. So even without fixing the problem of an undefined return code in case of an oom (and the imho more problematic ugly output of a (with gcc 4.9 colored) warning when compiling the kernel, it might be better to apply the patch.

Regards,

Alexander Holler
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/