From owner-freebsd-security@FreeBSD.ORG Tue Sep 15 16:08:22 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5F2EB1065672 for ; Tue, 15 Sep 2009 16:08:22 +0000 (UTC) (envelope-from des@des.no) Received: from tim.des.no (tim.des.no [194.63.250.121]) by mx1.freebsd.org (Postfix) with ESMTP id 201EF8FC17 for ; Tue, 15 Sep 2009 16:08:22 +0000 (UTC) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id 6BD406D44C; Tue, 15 Sep 2009 16:08:21 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id 503A18449F; Tue, 15 Sep 2009 18:08:21 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Przemyslaw Frasunek References: <4AAF4A64.3080906@thedarkside.nl> <86ab0w2z05.fsf@ds4.des.no> <4AAF8775.7000002@thedarkside.nl> <8663bk2xcb.fsf@ds4.des.no> <4AAFB465.4010901@frasunek.com> Date: Tue, 15 Sep 2009 18:08:21 +0200 In-Reply-To: <4AAFB465.4010901@frasunek.com> (Przemyslaw Frasunek's message of "Tue, 15 Sep 2009 17:36:05 +0200") Message-ID: <86y6ogtclm.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.0.95 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org, Pieter de Boer Subject: Re: Protecting against kernel NULL-pointer derefs X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Sep 2009 16:08:22 -0000 Przemyslaw Frasunek writes: > Dag-Erling Sm=C3=B8rgrav writes: > > A search of FreeBSD security advisories shows two in the last four > > years, plus the current unreleased issue. > There are three NULL pointer dereference issues, that I found in last > month, but probably more to come, so implementing some kind of zero page > protection should be considered. Feel free to *actually read what Pieter wrote and what I wrote in reply* EOD DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no