From owner-freebsd-security@FreeBSD.ORG Tue Sep 15 13:01:00 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 624901065693 for ; Tue, 15 Sep 2009 13:01:00 +0000 (UTC) (envelope-from pieter@thedarkside.nl) Received: from mail.thelostparadise.com (cl-92.ede-01.nl.sixxs.net [IPv6:2001:7b8:2ff:5b::2]) by mx1.freebsd.org (Postfix) with ESMTP id 2BFB38FC1B for ; Tue, 15 Sep 2009 13:01:00 +0000 (UTC) Received: from [88.159.10.42] (unknown [88.159.10.42]) by mail.thelostparadise.com (Postfix) with ESMTP id 52A8761C4B; Tue, 15 Sep 2009 15:00:59 +0200 (CEST) Message-ID: <4AAF900B.8010900@thedarkside.nl> Date: Tue, 15 Sep 2009 15:00:59 +0200 From: Pieter de Boer MIME-Version: 1.0 To: =?UTF-8?B?RGFnLUVybGluZyBTbcO4cmdyYXY=?= References: <4AAF4A64.3080906@thedarkside.nl> <86ab0w2z05.fsf@ds4.des.no> <4AAF8775.7000002@thedarkside.nl> <8663bk2xcb.fsf@ds4.des.no> In-Reply-To: <8663bk2xcb.fsf@ds4.des.no> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Cc: freebsd-security@freebsd.org Subject: Re: Protecting against kernel NULL-pointer derefs X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Sep 2009 13:01:00 -0000 Dag-Erling Smørgrav wrote: >> 'amount' => 2, 'of late' is more figure of speech than anything >> else. For me, amount was high enough to get interested and 'of late' >> may be because I've not been looking long enough. > > A search of FreeBSD security advisories shows two in the last four > years, plus the current unreleased issue. I agree that there is no > reason to allow applications to mmap() at address 0, but surely there > must be a better way to make your case than to sow FUD? I have no intention to sow FUD. Three such advisories is not much, but if there is a simple/inexpensive way to ensure that such bugs are not exploitable to gain root, I think 'we' should consider it. -- Pieter