<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8992811497323121233.post4884559622868011417..comments</id><updated>2011-12-07T18:39:29.152-08:00</updated><category term='ASLR'/><category term='sandbox'/><category term='Virtualisation'/><category term='the sky is falling'/><category term='VMware'/><category term='Linux'/><category term='vulnerability'/><category term='Presentation'/><category term='seccomp'/><category term='TSC'/><category term='Windows'/><category term='Security'/><category term='NetBSD'/><category term='Java'/><category term='Apple'/><category term='side-channel'/><title type='text'>Comments on cr0 blog: Linux NULL pointer dereference due to incorrect pr...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.cr0.org/feeds/4884559622868011417/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default?start-index=26&amp;max-results=25'/><author><name>Julien Tinnes</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4191701517809910736</id><published>2009-11-30T10:28:05.134-08:00</published><updated>2009-11-30T10:28:05.134-08:00</updated><title type='text'>I have no idea</title><content type='html'>I have no idea</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4191701517809910736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4191701517809910736'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1259605685134#c4191701517809910736' title=''/><author><name>saksit</name><uri>http://my2blog.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1516834774'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-8022891614627979357</id><published>2009-09-27T12:41:41.973-07:00</published><updated>2009-09-27T12:41:41.973-07:00</updated><title type='text'>@John: I have no idea what you&amp;#39;re talking abou...</title><content type='html'>@John: I have no idea what you&amp;#39;re talking about. We also worked on the patch, which was released even before the advisory.&lt;br /&gt;&lt;br /&gt;I even link to it from the blog post.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8022891614627979357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8022891614627979357'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1254080501973#c8022891614627979357' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4790640481199618502</id><published>2009-09-26T14:59:35.565-07:00</published><updated>2009-09-26T14:59:35.565-07:00</updated><title type='text'>Is it not normal procedure to inform the Kernel ma...</title><content type='html'>Is it not normal procedure to inform the Kernel maintainers before publishing an exploit to the world? It took until 13th August for a patch to be released.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4790640481199618502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4790640481199618502'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1254002375565#c4790640481199618502' title=''/><author><name>John Cooper</name><uri>http://www.blogger.com/profile/06524239861768487132</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1946112249'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-7863082871110836991</id><published>2009-09-07T14:15:24.640-07:00</published><updated>2009-09-07T14:15:24.640-07:00</updated><title type='text'>oo thanx bro. good bilgi..</title><content type='html'>oo thanx bro. good bilgi..</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7863082871110836991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7863082871110836991'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1252358124640#c7863082871110836991' title=''/><author><name>yenimoda</name><uri>http://yenimoda.blogspot.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1363849112'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-7640836854325901200</id><published>2009-08-27T03:33:01.888-07:00</published><updated>2009-08-27T03:33:01.888-07:00</updated><title type='text'>http://www.doecirc.energy.gov/bulletins/t-217.shtm...</title><content type='html'>http://www.doecirc.energy.gov/bulletins/t-217.shtml&lt;br /&gt;Julien can u give more info about this vuln and how to trigger it. &lt;br /&gt;thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7640836854325901200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7640836854325901200'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1251369181888#c7640836854325901200' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1254547070'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-1614731260664037698</id><published>2009-08-16T17:23:01.449-07:00</published><updated>2009-08-16T17:23:01.449-07:00</updated><title type='text'>It did exploit Fedora SELinux up until August 13, ...</title><content type='html'>It did exploit Fedora SELinux up until August 13, then was patched. I successfully exploited Kernel 2.6.29.6-213.fc11.i586 with this mechanism.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1614731260664037698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1614731260664037698'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250468581449#c1614731260664037698' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1335258274'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4795679951104962653</id><published>2009-08-16T02:30:29.104-07:00</published><updated>2009-08-16T02:30:29.104-07:00</updated><title type='text'>my fedora 11 with SELinux enforcing is also safe, ...</title><content type='html'>my fedora 11 with SELinux enforcing is also safe, the exploit doesnt work or did i miss something?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4795679951104962653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4795679951104962653'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250415029104#c4795679951104962653' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-402686648'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4245656617461373578</id><published>2009-08-15T23:43:41.435-07:00</published><updated>2009-08-15T23:43:41.435-07:00</updated><title type='text'>This definetly does not work on fedora with selinu...</title><content type='html'>This definetly does not work on fedora with selinux enforcing.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4245656617461373578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4245656617461373578'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250405021435#c4245656617461373578' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-244764927'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-2047105915716281797</id><published>2009-08-15T09:13:07.778-07:00</published><updated>2009-08-15T09:13:07.778-07:00</updated><title type='text'>Here&amp;#39;s a reply to some of the comments (not al...</title><content type='html'>Here&amp;#39;s a reply to some of the comments (not all, sorry):&lt;br /&gt;&lt;br /&gt;- @Anonymous: you&amp;#39;re correct, about SPARC. Interestingly, IA32 could also be safe but is not for performances reasons (unless you use Linux 2.0 or PaX KERNEXEC/UDEREF). x86_64 however killed segmentation :(&lt;br /&gt;- About mapping to Null. This should be protected by mmap_min_addr since Linux 2.6.23. Last month, &lt;a href="http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html" rel="nofollow"&gt;Tavis and I published a way to bypass it by using personalities&lt;/a&gt; and Pulseaudio. Brad Spengler then implemented this technique in an exploit and noticed that it worked even without the Pulseaudio trick. The reason was the default SELinux policy allowing unconfined users to mmap at address zero.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/2047105915716281797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/2047105915716281797'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250352787778#c2047105915716281797' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4593122475151228107</id><published>2009-08-15T08:06:25.221-07:00</published><updated>2009-08-15T08:06:25.221-07:00</updated><title type='text'>So there&amp;#39;s actually two bugs. One is NULL poin...</title><content type='html'>So there&amp;#39;s actually two bugs. One is NULL pointer dereference and the other is allowing to mmap (presumably unmmapable) memory at 0x0 location (even if /proc/sys/vm/mmap_min_addr &amp;gt; 0).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4593122475151228107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4593122475151228107'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250348785221#c4593122475151228107' title=''/><author><name>Emsi</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-437296486'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-6619958040596280757</id><published>2009-08-15T03:00:53.346-07:00</published><updated>2009-08-15T03:00:53.346-07:00</updated><title type='text'>Fedora&amp;#39;s SELinux policy (asuuming you leave it...</title><content type='html'>Fedora&amp;#39;s SELinux policy (asuuming you leave it enforcing) protects from the exploit (runcon can&amp;#39;t change the type).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6619958040596280757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6619958040596280757'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250330453346#c6619958040596280757' title=''/><author><name>Lam</name><uri>http://lac.pl/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-42784879'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-6626051252715677257</id><published>2009-08-14T13:43:16.343-07:00</published><updated>2009-08-14T13:43:16.343-07:00</updated><title type='text'>Doesn&amp;#39;t work with SELinux, although you claim ...</title><content type='html'>Doesn&amp;#39;t work with SELinux, although you claim the opposite in the source:&lt;br /&gt;&lt;br /&gt;sh wunderbar_emporium.sh &lt;br /&gt;runcon: invalid context:&lt;br /&gt;unconfined_u:unconfined_r:initrc_t:s0-s0:c0.c1023: Invalid argument&lt;br /&gt;UNABLE TO MAP ZERO PAGE!&lt;br /&gt;&lt;br /&gt;and the raw audit message for this:&lt;br /&gt;localhost.localdomain type=AVC msg=audit(1250278420.753:27501): avc: denied { mmap_zero } for pid=16933 comm=&amp;quot;exploit&amp;quot; scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=memprotect&lt;br /&gt;&lt;br /&gt;So obviously you were to fast when you thanked Dan for &amp;quot;great SELinux bypass&amp;quot;.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6626051252715677257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6626051252715677257'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250282596343#c6626051252715677257' title=''/><author><name>Christoph</name><uri>http://www.christoph-wickert.de</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1394232856'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-3426019353959305844</id><published>2009-08-14T12:46:38.877-07:00</published><updated>2009-08-14T12:46:38.877-07:00</updated><title type='text'>Looks like you where to fast when you thanked Dan,...</title><content type='html'>Looks like you where to fast when you thanked Dan, because SELinux does indeed stop this:&lt;br /&gt;&lt;br /&gt;$ LANG=C sh wunderbar_emporium.sh &lt;br /&gt;runcon: invalid context:&lt;br /&gt;unconfined_u:unconfined_r:initrc_t:s0-s0:c0.c1023: Invalid argument&lt;br /&gt;UNABLE TO MAP ZERO PAGE!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/3426019353959305844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/3426019353959305844'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250279198877#c3426019353959305844' title=''/><author><name>Christoph</name><uri>http://www.christoph-wickert.de</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1394232856'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-7751784777938742926</id><published>2009-08-14T12:29:18.170-07:00</published><updated>2009-08-14T12:29:18.170-07:00</updated><title type='text'>Why can&amp;#39;t the kernel track the process that ma...</title><content type='html'>Why can&amp;#39;t the kernel track the process that map page zero and does extra stuff when switching from user mode to kernel mode (update mmu to make it not excecutable, ...)&lt;br /&gt;&lt;br /&gt;Of course this will slowdown these processes but are there performance program that depend of that  ?&lt;br /&gt;Wine ?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7751784777938742926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7751784777938742926'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250278158170#c7751784777938742926' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1509691656'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-3374864548516784195</id><published>2009-08-14T12:04:12.233-07:00</published><updated>2009-08-14T12:04:12.233-07:00</updated><title type='text'>UNABLE TO MAP ZERO PAGE! on up to date Fedora with...</title><content type='html'>UNABLE TO MAP ZERO PAGE! on up to date Fedora with SELinux. Problem addressed by Red Hat when fixing CVE-2009-1895 recently?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/3374864548516784195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/3374864548516784195'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250276652233#c3374864548516784195' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-377742889'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-9122396991265219240</id><published>2009-08-14T08:32:18.250-07:00</published><updated>2009-08-14T08:32:18.250-07:00</updated><title type='text'>Don&amp;#39;t use the one from securityfocus, they hav...</title><content type='html'>Don&amp;#39;t use the one from securityfocus, they have an old version of the exploit.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/9122396991265219240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/9122396991265219240'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250263938250#c9122396991265219240' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-419559489'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-7098827952321881895</id><published>2009-08-14T07:13:50.390-07:00</published><updated>2009-08-14T07:13:50.390-07:00</updated><title type='text'>Looks like it&amp;#39;s finally kernel upgrade time!
G...</title><content type='html'>Looks like it&amp;#39;s finally kernel upgrade time!&lt;br /&gt;Goodbye Linux_2.6.19, I&amp;#39;ll miss you.&lt;br /&gt;&lt;br /&gt;Codifex</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7098827952321881895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/7098827952321881895'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250259230390#c7098827952321881895' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1849180430'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-6529838529876524164</id><published>2009-08-14T03:42:32.834-07:00</published><updated>2009-08-14T03:42:32.834-07:00</updated><title type='text'>Yet another reason to use some alternative with be...</title><content type='html'>Yet another reason to use some alternative with better track record wrt security, like Solaris or *BSD.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6529838529876524164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/6529838529876524164'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250246552834#c6529838529876524164' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1954245579'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-5525446194641169446</id><published>2009-08-14T01:20:42.120-07:00</published><updated>2009-08-14T01:20:42.120-07:00</updated><title type='text'>Congrats  for the discover !</title><content type='html'>Congrats  for the discover !</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/5525446194641169446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/5525446194641169446'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250238042120#c5525446194641169446' title=''/><author><name>Fanf</name><uri>http://www.blogger.com/profile/10948445494945956846</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='27' src='http://3.bp.blogspot.com/_9D3n-ZqzF48/SOsUcAHxfLI/AAAAAAAAAaw/ndHv1utBFFE/S220/photo_moi_petit.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-734348455'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-8414909420471404734</id><published>2009-08-14T01:12:17.499-07:00</published><updated>2009-08-14T01:12:17.499-07:00</updated><title type='text'>Can anybody explain why http://www.securityfocus.c...</title><content type='html'>Can anybody explain why http://www.securityfocus.com/bid/36038/exploit only works once?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8414909420471404734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8414909420471404734'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250237537499#c8414909420471404734' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1749231825'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-5831902960335175321</id><published>2009-08-13T21:39:50.614-07:00</published><updated>2009-08-13T21:39:50.614-07:00</updated><title type='text'>Exploit code has been available at http://grsecuri...</title><content type='html'>Exploit code has been available at http://grsecurity.net/~spender/wunderbar_emporium.tgz&lt;br /&gt;&lt;br /&gt;Works on all affected kernels: both x86 and x64, 4k stacks or 8k stacks, cred framework or not.  Disables SELinux, AppArmor, LSM, and auditing.  Also plays an embedded movie if the host is up to it.&lt;br /&gt;&lt;br /&gt;-Brad</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/5831902960335175321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/5831902960335175321'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250224790614#c5831902960335175321' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-419559489'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-1865853825923569247</id><published>2009-08-13T19:23:24.738-07:00</published><updated>2009-08-13T19:23:24.738-07:00</updated><title type='text'>Good find, great work.</title><content type='html'>Good find, great work.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1865853825923569247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1865853825923569247'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250216604738#c1865853825923569247' title=''/><author><name>nojoy</name><uri>http://sdf.lonestar.org</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1573544349'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-8851909123986181383</id><published>2009-08-13T18:04:52.123-07:00</published><updated>2009-08-13T18:04:52.123-07:00</updated><title type='text'>&amp;gt; This is one reason so many 64b systems
&amp;gt; (...</title><content type='html'>&amp;gt; This is one reason so many 64b systems&lt;br /&gt;&amp;gt; (Tru64 on Alpha being a good example&lt;br /&gt;&amp;gt; prevent mapping the first 32 bits of&lt;br /&gt;&amp;gt; address space. Surprising that Linux&lt;br /&gt;&amp;gt; doesn&amp;#39;t do the same.&lt;br /&gt;&lt;br /&gt;?? First of all - the whole problem has nothing to do with architecture of the used CPU (intel, non-intel, 32bit, 64bit).&lt;br /&gt;&lt;br /&gt;Secondly - Linux also offers such protection, but it was somehow flawed until one of the kernel versions&lt;br /&gt;&lt;br /&gt;3rdly - It is guaranteed on some systems (SVR4) that the fisrt page is always mapped (PROT_READ afair), so linux tries to emulate that behavior via the personality mechanism - http://linux.die.net/man/2/personality - and that is where the bug lied (the one with mapping zero page).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8851909123986181383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/8851909123986181383'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250211892123#c8851909123986181383' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-112379156'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-4665788823320262693</id><published>2009-08-13T15:59:16.515-07:00</published><updated>2009-08-13T15:59:16.515-07:00</updated><title type='text'>This is one reason so many 64b systems (Tru64 on A...</title><content type='html'>This is one reason so many 64b systems (Tru64 on Alpha being a good example) prevent mapping the first 32 bits of address space. Surprising that Linux doesn&amp;#39;t do the same.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4665788823320262693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/4665788823320262693'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250204356515#c4665788823320262693' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-264143035'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-1351693715162811842</id><published>2009-08-13T14:56:18.788-07:00</published><updated>2009-08-13T14:56:18.788-07:00</updated><title type='text'>http://www.securityfocus.com/bid/36038/exploit
bee...</title><content type='html'>http://www.securityfocus.com/bid/36038/exploit&lt;br /&gt;beer please now</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1351693715162811842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/4884559622868011417/comments/default/1351693715162811842'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html?showComment=1250200578788#c1351693715162811842' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-4884559622868011417' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/4884559622868011417' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-753387682'/></entry></feed>
