|
Message-ID: <224296305.115231290443560699.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com> Date: Mon, 22 Nov 2010 11:32:40 -0500 (EST) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads Please use CVE-2010-4243 Thanks. -- JB ----- "Eugene Teo" <eugene@...hat.com> wrote: > This is the OOM dodging issue that can be triggered with Brad's > reproducer at http://grsecurity.net/~spender/64bit_dos.c. Written > in the comments: "The second bug here is that the memory usage > explodes > within the kernel from a single 128k allocation in userland The > explosion of memory isn't accounted for by any task so it won't be > terminated by the OOM killer." > > I don't recall seeing a CVE name assigned to this, so please assign > one. > Upstream is still attempting to fix this. > > https://bugzilla.redhat.com/show_bug.cgi?id=625688#c0 > > Thanks, Eugene
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.