Buggy CVE-2017-1000364 patches segfaulting embedded VMs

2017-06-23 Thread Moritz Bechler
Hi, not sure whether this is the right list for this, but just so that maybe not everybody has to figure this out on his own, The custom kernel patches currently deployed by various Linux distributions (from the looks of it at least RedHat, SUSE, Debian and Ubuntu) for CVE-2017-1000364/Stack Clas

Re: RFR [9] 8056152 API to create Threads that do not inherit InheritableThreadLocals

2015-12-08 Thread Moritz Bechler
Hi, > Many threads created by the platform are short lived and perform some > simple async operation on behalf of the platform. These threads typically > use/extend sun.misc.ManagedLocalsThread. This is a convenient internal > API that can be used to create threads that do not wish to inherit initi

(De-)serialization, quo vadis

2015-11-23 Thread Moritz Bechler
Hi, I'm not absolutely sure this is the best place to have this discussion (pointers welcome), but it's the most appropriate I figured out so far. In the light of the most recent code execution vulnerabilities through arbitrary object deserialization - and the follow-ups that I can guarantee you