Linux splice_write Kernel Panic

Discussion in 'News Aggregator' started by Packet Storm, 13 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4 filesystem. This is proof of concept code that triggers the kernel panic.

    Continue reading...
     

Share This Page

Loading...