I've committed a change that prevents executing set*id binaries with no args as discussed. The link below is factually incorrect because it says that BSD's already disallow this. christos > On Feb 4, 2022, at 6:25 PM, Jan Schaumann <jschauma%netmeister.org@localhost> wrote: > > The following reply was made to PR kern/56673; it has been noted by GNATS. > > From: Jan Schaumann <jschauma%netmeister.org@localhost> > To: gnats-bugs%netbsd.org@localhost, kern-bug-people%netbsd.org@localhost > Cc: > Subject: Re: kern/56673: don't allow execve with NULL argv > Date: Fri, 4 Feb 2022 18:21:51 -0500 > > FWIW, here's a summary of the same discussion on > the linux-kernel mailing list: > > https://lwn.net/SubscriberLink/882799/cb8f313c57c6d8a6/ > > https://lwn.net/ml/linux-kernel/20220126043947.10058-1-ariadne%dereferenced.org@localhost/ >
Attachment:
signature.asc
Description: Message signed with OpenPGP