Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At least these (seem to) result in a kernel panic instead of privileged escalation or reading unauthorized memory.

But in a world where even djbdns had a (minor) security issue, I don't think it's reasonable to expect any non-trivial software—particularly software written in C—to be fully secure.



I found it interesting that most of the patches are one or two line changes. Shows how one tiny oversight can open up a DoS or security vulnerablity.


The mmap_panic one does seem to have the possibility of privilege escalation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: