CVSROOT:        /cvs
Module name:    src
Changes by:     dera...@cvs.openbsd.org 2022/08/29 11:00:30

Modified files:
        sbin/dhcpleased: Makefile 
        sbin/mountd    : Makefile 
        sbin/nfsd      : Makefile 
        sbin/pflogd    : Makefile 
        sbin/resolvd   : Makefile 
        sbin/slaacd    : Makefile 
        sbin/unwind    : Makefile 

Log message:
Dynamically link these /sbin daemons: dhcpleased, mountd, nfsd, pflogd,
resolvd, slaacd, unwind.
The mitigation story is way better: syscalls are in a randomly located
libc, and every syscall stub is randomly located inside that due to
random relinking.  As opposed to fixed offset inside a release binary.
There is one known consequence: /usr nfs mounting must use statically
configured IP addresses.
ok kettenis florian, others

Reply via email to