Ancestors

Written by Jann Horn on 2024-09-07 at 00:48

I added code to Linux to help KASAN detect specific types of UAFs more reliably (https://git.kernel.org/pub/scm/linux/kernel/git/vbabka/slab.git/commit/?h=slab/for-6.12/rcu_barriers&id=b8c8ba73c68bb3c3e9dad22f488b86c540c839f9), it's been in the linux-next integration tree for, I don't know, a month or so maybe (though it's not in the mainline tree yet), and still there are zero hits on LKML of bugs caught where the stack trace involves my detection...

It's nice that there apparently aren't a lot of easy-to-find bugs of this type around but it's also a little disappointing to not immediately get some nice results from my work...

=> More informations about this toot | More toots from jann@infosec.exchange

Written by Damien Miller on 2024-09-07 at 00:55

@jann the defenders' dilemma...

=> More informations about this toot | More toots from djm@cybervillains.com

Written by Jann Horn on 2024-09-07 at 01:25

@djm if it's not blowing up before the change, and it's not blowing up after the change, has anything really changed

=> More informations about this toot | More toots from jann@infosec.exchange

Written by Frederik Braun � on 2024-09-07 at 07:42

@jann @djm defense work sucks in that regard :-( on the flip-side, you can take pride in knowing that future kernels will never have that kind of simple uaf bugs. ever. 😊

=> More informations about this toot | More toots from freddy@security.plumbing

Toot

Written by Jann Horn on 2024-09-07 at 13:25

@freddy @djm the detection is not that good, sadly...

=> More informations about this toot | More toots from jann@infosec.exchange

Descendants

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113096494171121515
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
270.869182 milliseconds
Gemini-to-HTML Time
0.772565 milliseconds

This content has been proxied by September (3851b).