Loading glibc in a new namespace fails vtable check

Moshe Rubin moshe.rubin@gmail.com
Mon Sep 30 14:48:28 GMT 2024


Hi Florian,

Will you be opening a ticket for this bug, or do I need to do it?

Best regards,

Moshe

On Sun, Sep 29, 2024 at 4:03 PM Florian Weimer <fweimer@redhat.com> wrote:

> * Moshe Rubin:
>
> > If a stream (e.g., stderr) can be passed from an initial libc to a
> > secondary one, then why did my production app throw a fatal error?
>
> I don't know, sorry.
>
> > I was passing an initial stderr to a secondary function pointer which,
> > if I understand you, should have been just fine.
>
> Yes, that should work.
>
> > What does glibc check for to prevent hacking, and how dod my app
> > violate the terms?
>
> If glibc encounters an unknown vtable pointer, it checks if the
> accessing stdio function is in a secondary namespace (not the initial
> libc).  In that case, execution proceeds, and the unknown vtable pointer
> is accepted.  If it is in the initial namespace, glibc terminates with a
> fatal error.
>
> There is another mechanism that disables checks entirely for the initial
> namespace, but it is only used for very old programs (so old that most
> currently used architectures did not exist back then).
>
> Thanks,
> Florian
>
>


More information about the Libc-help mailing list