Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Greg KH
On Mon, Mar 19, 2007 at 03:01:25PM -0700, Chris Wright wrote: > * Greg KH ([EMAIL PROTECTED]) wrote: > > From: Chris Wright <[EMAIL PROTECTED]> > > > > [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak > > > > User supplied len < 0 can cause leak of kernel memory. > > Use unsigned compare

Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread David Miller
From: Chris Wright <[EMAIL PROTECTED]> Date: Mon, 19 Mar 2007 15:01:25 -0700 > * Greg KH ([EMAIL PROTECTED]) wrote: > > From: Chris Wright <[EMAIL PROTECTED]> > > > > [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak > > > > User supplied len < 0 can cause leak of kernel memory. > > Use

Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Chris Wright
* Greg KH ([EMAIL PROTECTED]) wrote: > From: Chris Wright <[EMAIL PROTECTED]> > > [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak > > User supplied len < 0 can cause leak of kernel memory. > Use unsigned compare instead. You can drop this one. It's dependent on a patch that is not in

[patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Greg KH
-stable review patch. If anyone has any objections, please let us know. -- From: Chris Wright <[EMAIL PROTECTED]> [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak User supplied len < 0 can cause leak of kernel memory. Use unsigned compare instead. Signed-off-by: Chris

[patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Greg KH
-stable review patch. If anyone has any objections, please let us know. -- From: Chris Wright [EMAIL PROTECTED] [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak User supplied len 0 can cause leak of kernel memory. Use unsigned compare instead. Signed-off-by: Chris Wright

Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Chris Wright
* Greg KH ([EMAIL PROTECTED]) wrote: From: Chris Wright [EMAIL PROTECTED] [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak User supplied len 0 can cause leak of kernel memory. Use unsigned compare instead. You can drop this one. It's dependent on a patch that is not in 2.6.20.

Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread David Miller
From: Chris Wright [EMAIL PROTECTED] Date: Mon, 19 Mar 2007 15:01:25 -0700 * Greg KH ([EMAIL PROTECTED]) wrote: From: Chris Wright [EMAIL PROTECTED] [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak User supplied len 0 can cause leak of kernel memory. Use unsigned compare

Re: [patch 03/31] Fix user copy length in ipv6_sockglue.c

2007-03-19 Thread Greg KH
On Mon, Mar 19, 2007 at 03:01:25PM -0700, Chris Wright wrote: * Greg KH ([EMAIL PROTECTED]) wrote: From: Chris Wright [EMAIL PROTECTED] [IPV6] fix ipv6_getsockopt_sticky copy_to_user leak User supplied len 0 can cause leak of kernel memory. Use unsigned compare instead. You can