Re: [Full-disclosure] FreeBSD <= 6.1 kqueue() NULL pointer dereference

2009-09-14 Thread Przemyslaw Frasunek
Przemyslaw Frasunek pisze: > FreeBSD <= 6.1 suffers from classical check/use race condition on SMP There is yet another kqueue related vulnerability. It affects 6.x, up to 6.4-STABLE. FreeBSD security team was notified on 29th Aug, but there is no response until now, so I won't publish any details

FreeBSD <= 6.1 kqueue() NULL pointer dereference

2009-08-24 Thread Przemyslaw Frasunek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 FreeBSD <= 6.1 suffers from classical check/use race condition on SMP systems in kevent() syscall, leading to kernel mode NULL pointer dereference. It can be triggered by spawning two threads: 1st thread looping on open() and close() syscalls, and the