watch structure

Steve Grubb sgrubb at redhat.com
Tue Apr 5 15:10:44 UTC 2005


On Tuesday 05 April 2005 11:00, Casey Schaufler wrote:
> But you don't know how much to copy.

Sure you do. The lengths are in 2 other fields of the same structure. When 
using this scheme, you have to verify the length of the netlink packet meshes 
with the lengths provided or reject it. This technique does increase the 
amount of checking before using the data.

-Steve




More information about the Linux-audit mailing list