[LTP] [PATCH v2] syscalls/timer_create: Add test for CVE-2017-18344

Petr Vorel pvorel@suse.cz
Mon Jul 29 13:21:52 CEST 2019


Hi Christian,

> In kernels prior to 4.14.8 (missing commit cef31d9af908)
> the sigevent.sigev_notify field is not properly checked
> when creating a timer using timer_create(2).
> This can be used to read arbitrary kernel memory.

Thanks for your patch, merged into master (with Cyril's and Li's ack).

Kind regards,
Petr


More information about the ltp mailing list