[7412] in bugtraq
Re: Fwd: Any user can panic OpenBSD machine
daemon@ATHENA.MIT.EDU (Chris Wedgwood)
Tue Jul 28 12:22:03 1998
Date: Tue, 28 Jul 1998 14:09:53 +1200
Reply-To: Chris Wedgwood <chris@CYBERNET.CO.NZ>
From: Chris Wedgwood <chris@CYBERNET.CO.NZ>
X-To: Scott Stone <sstone@ume.pht.co.jp>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <Pine.LNX.3.96LJ1.1b7.980728105738.20871y-100000@ume.pht.co.jp>;
from Scott Stone on Tue, Jul 28, 1998 at 10:57:52AM +0900
On Tue, Jul 28, 1998 at 10:57:52AM +0900, Scott Stone wrote:
> it returns EINVAL on NetBSD - Linux's behavior could well be different.
I wasn't very clear.
Yes, EINVAL is returned by NetBSD - but this is a bug itself. The API uses
unsigned lengths, so -1 isn't a bogus value (well, perhaps it is actually,
if you consider the fact that buffer_start + 0xFFFFFFFFul) >= process space
end address, then EINVAL is legitimate).
-cw