[PATCH] rtld: Reject overly long LD_AUDIT path elements

Florian Weimer fweimer@redhat.com
Thu Jun 29 19:05:00 GMT 2017


On 06/26/2017 02:57 PM, Andreas Schwab wrote:
> On Jun 26 2017, Florian Weimer <fweimer@redhat.com> wrote:
> 
>> The goal is to prevent massaging the heap through LD_AUDIT variable
>> contents.  So it's purely hardening.
> 
> Why is that needed?

I'm not sure if it is needed.  I am not an experienced exploit writer.

I assume you want me to apply something like the attached patch, right?

Thanks,
Florian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ld_audit.patch
Type: text/x-patch
Size: 6708 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20170629/ea3f6d57/attachment.bin>


More information about the Libc-alpha mailing list