Loading glibc in a new namespace fails vtable check
Florian Weimer
fweimer@redhat.com
Sun Sep 29 13:03:33 GMT 2024
* Moshe Rubin:
> If a stream (e.g., stderr) can be passed from an initial libc to a
> secondary one, then why did my production app throw a fatal error?
I don't know, sorry.
> I was passing an initial stderr to a secondary function pointer which,
> if I understand you, should have been just fine.
Yes, that should work.
> What does glibc check for to prevent hacking, and how dod my app
> violate the terms?
If glibc encounters an unknown vtable pointer, it checks if the
accessing stdio function is in a secondary namespace (not the initial
libc). In that case, execution proceeds, and the unknown vtable pointer
is accepted. If it is in the initial namespace, glibc terminates with a
fatal error.
There is another mechanism that disables checks entirely for the initial
namespace, but it is only used for very old programs (so old that most
currently used architectures did not exist back then).
Thanks,
Florian
More information about the Libc-help
mailing list