[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [RFC][PATCH] linux-2.6.2-rc2_vsyscall-gtod_B1.patch


Ulrich Drepper wrote:
> You got to be kidding.  Some object fixed in the address space which can
> perform system calls.  Nothing is more welcome to somebody trying to
> exploit some bugs.

Two approaches to randomising the vdso address:

  1. Selecting a random address at boot time.  All tasks have the same
     vdso for that run of the kernel.  Advantages: no MSR write at
     each context switch; could patch libsyscall.so at boot time with
     address if we were fanatical about optimisation (i.e. other
     libcs, not Glibc :)  Disadvantages: the attacker may eventually
     learn the address.

  2. Select a random address for every new task.  Advantages: harder
     to guess from studying a machine for a long time.  Disadvantages:
     slower context switches; the gain from randomising each task is
     nothing if all the tasks are very long lived anyway.

-- Jamie
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo _at_ vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/


この情報があなたの探していたものかどうか選択してください。
yes/まさにこれだ!   no/違うなぁ   part/一部見つかった   try/これで試してみる

あなたが探していた情報はどのようなことか、ご自由に記入下さい。特に「まさにこれだ!」と言う場合は記入をお願いします。
例:「複数のマシンからCATV経由でipmasqueradeを利用してWebを参照したい場合の設定について」
Follow-Ups: References: