From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail137.messagelabs.com (mail137.messagelabs.com [216.82.249.19]) by kanga.kvack.org (Postfix) with SMTP id 70DF86B00E1 for ; Wed, 3 Jun 2009 15:42:35 -0400 (EDT) Received: from localhost (smtp.ultrahosting.com [127.0.0.1]) by smtp.ultrahosting.com (Postfix) with ESMTP id EB1C182CD28 for ; Wed, 3 Jun 2009 15:57:19 -0400 (EDT) Received: from smtp.ultrahosting.com ([74.213.175.254]) by localhost (smtp.ultrahosting.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pobt1zyS7U5u for ; Wed, 3 Jun 2009 15:57:19 -0400 (EDT) Received: from gentwo.org (unknown [74.213.171.31]) by smtp.ultrahosting.com (Postfix) with ESMTP id B1B6182CD2E for ; Wed, 3 Jun 2009 15:57:13 -0400 (EDT) Date: Wed, 3 Jun 2009 15:42:13 -0400 (EDT) From: Christoph Lameter Subject: Re: Security fix for remapping of page 0 (was [PATCH] Change ZERO_SIZE_PTR to point at unmapped space) In-Reply-To: <7e0fb38c0906031214lf4a2ed2x688da299e8cb1034@mail.gmail.com> Message-ID: References: <20090530230022.GO6535@oblivion.subreption.com> <20090603182949.5328d411@lxorguk.ukuu.org.uk> <20090603180037.GB18561@oblivion.subreption.com> <20090603183939.GC18561@oblivion.subreption.com> <7e0fb38c0906031214lf4a2ed2x688da299e8cb1034@mail.gmail.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-linux-mm@kvack.org To: Eric Paris Cc: Linus Torvalds , "Larry H." , Alan Cox , linux-mm@kvack.org, Rik van Riel , linux-kernel@vger.kernel.org, pageexec@freemail.hu List-ID: On Wed, 3 Jun 2009, Eric Paris wrote: > NAK with SELinux on you now need both the SELinux mmap_zero > permission and the CAP_SYS_RAWIO permission. Previously you only > needed one or the other, depending on which was the predominant > LSM..... CAP_SYS_RAWIO is checked so you only need to check for mmap_zero in SELinux. > Even if you want to argue that I have to take CAP_SYS_RAWIO in the > SELinux case what about all the other places? do_mremap? do_brk? > expand_downwards? brk(0) would free up all the code? The others could be added. -- To unsubscribe, send a message with 'unsubscribe linux-mm' in the body to majordomo@kvack.org. For more info on Linux MM, see: http://www.linux-mm.org/ . Don't email: email@kvack.org