From owner-freebsd-security@FreeBSD.ORG Tue Sep 15 12:06:35 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E3D751065670 for ; Tue, 15 Sep 2009 12:06:35 +0000 (UTC) (envelope-from des@des.no) Received: from tim.des.no (tim.des.no [194.63.250.121]) by mx1.freebsd.org (Postfix) with ESMTP id A74D88FC1A for ; Tue, 15 Sep 2009 12:06:35 +0000 (UTC) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id AA0AA6D41B; Tue, 15 Sep 2009 12:06:34 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id 81108844F3; Tue, 15 Sep 2009 14:06:34 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Pieter de Boer References: <4AAF4A64.3080906@thedarkside.nl> Date: Tue, 15 Sep 2009 14:06:34 +0200 In-Reply-To: <4AAF4A64.3080906@thedarkside.nl> (Pieter de Boer's message of "Tue, 15 Sep 2009 10:03:48 +0200") Message-ID: <86ab0w2z05.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.0.95 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: Protecting against kernel NULL-pointer derefs X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Sep 2009 12:06:36 -0000 Pieter de Boer writes: > Given the amount of NULL-pointer dereference vulnerabilities in the > FreeBSD kernel that have been discovered of late, Specify "amount" and define "of late". > By disallowing userland to map pages at address 0x0 (and a bit beyond), > it is possible to make such NULL-pointer deref bugs mere DoS'es instead > of code execution bugs. Linux has implemented such a protection for a > long while now, by disallowing page mappings on 0x0 - 0xffff. Yes, that really worked out great for them: http://isc.sans.org/diary.html?storyid=3D6820 DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no