Re: Panic from bad length parameter in bind (Possible DOS attack)

From: Ryan Sommers (ryans_at_gamersimpact.com)
Date: 04/04/04

  • Next message: Conrad J. Sabatier: "buildworld failure"
    Date: Sun, 4 Apr 2004 13:59:34 -0600 (MDT)
    To: "Pawel Jakub Dawidek" <pjd@FreeBSD.org>
    
    

    Pawel Jakub Dawidek said:
    > On Sat, Apr 03, 2004 at 02:21:08PM -0700, Ryan Sommers wrote:
    > +> Whenever I supply a length of 4 as the final bind parameter I get the
    > +> following panic. Looks like bind returns fine, however, when the
    > program
    > +> exits it stumbles over some mutex associated with the descriptor. The
    > +> mutex passed to mtx_destroy() has MTX_RECURSED set. I attempted to find
    > +> where the call to bind was clobbering the mutex but couldn't. I
    > attached
    > +> the simple program to exploit this. I was able to do it as a regular
    > user.
    >
    > Yes, could you try this patch:
    >
    > http://people.freebsd.org/~pjd/patches/tcp_usrreq.c.patch

    That fixes it.

    >
    > --
    > Pawel Jakub Dawidek http://www.FreeBSD.org
    > pjd@FreeBSD.org http://garage.freebsd.pl
    > FreeBSD committer Am I Evil? Yes, I Am!
    >

    --
    Ryan Sommers
    ryans@gamersimpact.com
    _______________________________________________
    freebsd-current@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-current
    To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
    

  • Next message: Conrad J. Sabatier: "buildworld failure"

    Relevant Pages

    • Re: ataraid panic
      ... On 2004.07.27 23:05:59 +0200, Pawel Jakub Dawidek wrote: ... > Could you try this patch: ... This fixes the panic for me. ... FreeBSD Documentation Team ...
      (freebsd-current)
    • [stephane.wirtel@belgacom.net: Re: [current tinderbox] failure on i386/i386]
      ... The patch of Pawel Jakub Dawidek, fixes the problem. ... To unsubscribe, ...
      (freebsd-current)
    • 2.6.10-as5
      ... Lots of security fixes in here; it's probably a good idea to upgrade. ... Patch stolen from ubuntu. ... skb header corruption. ... struct, when it should be using a compat_cmsghdr struct, instead. ...
      (Linux-Kernel)
    • RE: [Full-Disclosure] 3 new MS patches next week... but none fix
      ... MS does beta test fixes, some companies could be on that beta test program. ... If the company had a real patch that they developed from detailed purchased ... something they called "virtual patches", which he was quite smug about. ...
      (Full-Disclosure)
    • Re: Fixes for nforce2 hard lockup, apic, io-apic, udma133 covered
      ... Trying to get a grasp on the all the fixes floating around. ... So the consensus seems to be that Ross's timer patch and the ... and one with those fixes and Maciej's acpi fixes below. ...
      (Linux-Kernel)