Report Double Fetch Bug Found in Linux-4.6.1/kernel/auditsc.c

Oleg Nesterov oleg at redhat.com
Mon Jun 20 19:18:14 UTC 2016


Not that I understand this report, but

On 06/20, Richard Guy Briggs wrote:
>
> This function is only ever called by __audit_free(), which is only ever
> called on failure of task creation or on exit of the task, so in neither
> case can anything else change it.

How so?

Another thread or CLONE_VM task or /proc/pid/mem can change the user-space
memory in parallel.

Oleg.




More information about the Linux-audit mailing list