Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <224296305.115231290443560699.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 22 Nov 2010 11:32:40 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: kernel: mm: mem allocated invisible
 to oom_kill() when not attached to any threads

Please use CVE-2010-4243

Thanks.

-- 
    JB


----- "Eugene Teo" <eugene@...hat.com> wrote:

> This is the OOM dodging issue that can be triggered with Brad's 
> reproducer at http://grsecurity.net/~spender/64bit_dos.c. Written
> in the comments: "The second bug here is that the memory usage
> explodes 
> within the kernel from a single 128k allocation in userland The 
> explosion of memory isn't accounted for by any task so it won't be 
> terminated by the OOM killer."
> 
> I don't recall seeing a CVE name assigned to this, so please assign
> one. 
> Upstream is still attempting to fix this.
> 
> https://bugzilla.redhat.com/show_bug.cgi?id=625688#c0
> 
> Thanks, Eugene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.