RFC: Too many race conditions.

Florian Weimer fw@deneb.enyo.de
Sun May 20 22:58:00 GMT 2007


* Andrew Haley:
> Hmm. This depends, does it not, on the fact that a blocking call does
> not return when a file descriptor is closed? This sounds to me like a
> bug in the kernel,

I think the fundamental issue is that the object associated with the
descriptor might change before the system call is even issued.
> Is this an exploitable security hole? I suppose it is.

Yes, that is my hunch as well. Which means that it needs to be fixed
if you ever want to support mobile code.


More information about the Java mailing list

AltStyle によって変換されたページ (->オリジナル) /