3 ms·
that's correct, versions prior to 4.12 are not affected
by Da5hes 9y ago
that's correct, versions prior to 4.12 are not affected
- userbinator 9y agoThis is 4.11: https://elixir.free-electrons.com/linux/v4.11/source/kernel/exit.c https://elixir.free-electrons.com/linux/v4.11/source/kernel/... The code is significantly different but I still see a lack of access_ok(), so was the checking performed somewhere else that I didn't notice (I haven't looked closely at this part of the kernel before)?
- Da5hes 9y agoit is the use of unsafe_put_user without access_ok(), not access_ok() alone
- icebraining 9y agoIIUC, you only need the access_ok() when using the new unsafe_put_user(). That code is still using put_user().
- deleted 9y ago[deleted]