Search String: Display: Description: Sort:

Results:

References: [ +subject:/^(?:^\s*(re|sv|fwd|fw)[\[\]\d]*[:>-]+\s*)*\[PATCH\]\s+IPV6_CHECKSUM\s+socket\s+option\s+can\s+corrupt\s+kernel\s+memory\s*$/: 28 ]

Total 28 documents matching your query.

1. [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: David Stevens <dlstevens@xxxxxxxxxx>
Date: Tue, 12 Apr 2005 17:41:25 -0600
I was doing some testing with IPV6_CHECKSUM and started getting memory corruption (panic when the socket was closed). The bug originally manifested itself as a the "csum" pointer in rawv6_push_pendin
/archives/netdev/2005-04/msg00517.html (11,978 bytes)

2. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: YOSHIFUJI Hideaki / 吉藤英明 <yoshfuji@xxxxxxxxxxxxxx>
Date: Wed, 13 Apr 2005 09:53:08 +0900 (JST)
Please geive up the "singed-off" line. Anyway, how about this? Signed-off-by: Hideaki YOSHIFUJI <yoshfuji@xxxxxxxxxxxxxx> == net/ipv6/raw.c 1.80 vs edited == -- 1.80/net/ipv6/raw.c 2005-03-27 08:04:3
/archives/netdev/2005-04/msg00519.html (11,375 bytes)

3. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: xxxxxx>
Date: Tue, 12 Apr 2005 19:45:34 -0700
YOSHIFUJI Hideaki / 吉藤英明 <yoshfuji@xxxxxxxxxxxxxx> wrote on 05:53:08 PM: Signed-off-by: David L Stevens <dlstevens@xxxxxxxxxx> csum has to be a pointer into the packet data, so it can store the check
/archives/netdev/2005-04/msg00521.html (11,933 bytes)

4. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: xxxxxx>
Date: Wed, 13 Apr 2005 13:05:35 +0900 (JST)
tp://ww
/archives/netdev/2005-04/msg00523.html (10,763 bytes)

5. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: xxxxxxxxxxxxxx>
Date: Tue, 12 Apr 2005 22:07:06 -0700
-ipv6.o
/archives/netdev/2005-04/msg00525.html (11,491 bytes)

6. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: ote@xxxxxxxxxx>
Date: Thu, 14 Apr 2005 22:26:13 +1000
no dou
/archives/netdev/2005-04/msg00550.html (18,487 bytes)

7. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: xxxxxxxxxxxxxx>
Date: Thu, 14 Apr 2005 21:34:32 +0900 (JST)
f skb_c
/archives/netdev/2005-04/msg00551.html (10,798 bytes)

8. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: n <ganesh.venkatesan@xxxxxxxxx>
Date: Thu, 14 Apr 2005 12:36:46 -0600
ing iss
/archives/netdev/2005-04/msg00557.html (11,476 bytes)

9. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: Starr <shawn.starr@xxxxxxxxxx>
Date: Fri, 15 Apr 2005 07:30:40 +1000
Apr 13
/archives/netdev/2005-04/msg00561.html (11,869 bytes)

10. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: u <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Thu, 14 Apr 2005 15:43:37 -0700
f? This
/archives/netdev/2005-04/msg00562.html (12,183 bytes)

11. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: x>
Date: Fri, 15 Apr 2005 09:22:27 +1000
rian --
/archives/netdev/2005-04/msg00564.html (13,021 bytes)

12. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: u <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Thu, 14 Apr 2005 17:31:38 -0700
e rawv6
/archives/netdev/2005-04/msg00565.html (13,014 bytes)

13. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: Stevens <dlstevens@xxxxxxxxxx>
Date: Fri, 15 Apr 2005 10:41:02 +1000
alls ra
/archives/netdev/2005-04/msg00566.html (10,905 bytes)

14. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: Jean Tourrilhes <jt@xxxxxxxxxx>
Date: Fri, 15 Apr 2005 13:42:56 -0700
cause I
/archives/netdev/2005-04/msg00576.html (10,425 bytes)

15. [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: David Stevens <dlstevens@xxxxxxxxxx>
Date: Tue, 12 Apr 2005 17:41:25 -0600
I was doing some testing with IPV6_CHECKSUM and started getting memory corruption (panic when the socket was closed). The bug originally manifested itself as a the "csum" pointer in rawv6_push_pendin
/archives/netdev/2005-04/msg01653.html (11,978 bytes)

16. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: YOSHIFUJI Hideaki / <yoshfuji@xxxxxxxxxxxxxx>
Date: Wed, 13 Apr 2005 09:53:08 +0900 (JST)
Please geive up the "singed-off" line. Anyway, how about this? Signed-off-by: Hideaki YOSHIFUJI <yoshfuji@xxxxxxxxxxxxxx> == net/ipv6/raw.c 1.80 vs edited == -- 1.80/net/ipv6/raw.c 2005-03-27 08:04:3
/archives/netdev/2005-04/msg01655.html (11,520 bytes)

17. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: David Stevens <dlstevens@xxxxxxxxxx>
Date: Tue, 12 Apr 2005 19:45:34 -0700
YOSHIFUJI Hideaki / <yoshfuji@xxxxxxxxxxxxxx> wrote on 04/12/2005 05:53:08 PM: Signed-off-by: David L Stevens <dlstevens@xxxxxxxxxx> csum has to be a pointer into the packet data, so it can store the
/archives/netdev/2005-04/msg01657.html (11,989 bytes)

18. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: YOSHIFUJI Hideaki / <yoshfuji@xxxxxxxxxxxxxx>
Date: Wed, 13 Apr 2005 13:05:35 +0900 (JST)
Ok, understood. BTW, I remember that my first intention was that we restrict "checksum" should be placed within the first fragment. In this sense, rp->offset + 1 < len does not make sense to me, if t
/archives/netdev/2005-04/msg01659.html (10,935 bytes)

19. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: David Stevens <dlstevens@xxxxxxxxxx>
Date: Tue, 12 Apr 2005 22:07:06 -0700
netdev-bounce@xxxxxxxxxxx wrote on 04/12/2005 09:05:35 PM: <OF0A4F590E.3F5A449F-ON88256FE2.000E49F8-88256FE2.000F289A@xxxxxxx These aren't fragments in the packet sense, of course. These are just dif
/archives/netdev/2005-04/msg01661.html (11,533 bytes)

20. Re: [PATCH] IPV6_CHECKSUM socket option can corrupt kernel memory (score: 1)
Author: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Thu, 14 Apr 2005 22:26:13 +1000
Yes it is possible to get nr_frags != 0. We also need to handle the case where there are multiple packets on sk_write_queue. So here is a patch that introduces skb_store_bits -- the opposite of skb_c
/archives/netdev/2005-04/msg01686.html (18,597 bytes)


This search system is powered by Namazu