Report Double Fetch Bug Found in Linux-4.6.1/kernel/auditsc.c

Paul Moore paul at paul-moore.com
Mon Jun 27 21:45:41 UTC 2016


On Wed, Jun 22, 2016 at 5:57 AM, Pengfei Wang <wpengfeinudt at gmail.com> wrote:
> Agreed, buffer the string at the first round and use it instead of recopying
> it a second time from user space would keep it safe, which is the easiest way I
> think. Please fix it, thanks!

FYI: I've created a new issue on GitHub to track this:

 * https://github.com/linux-audit/audit-kernel/issues/18

-- 
paul moore
www.paul-moore.com




More information about the Linux-audit mailing list