Fork us on GitHub Follow us on Google+ Follow us on Facebook Follow us on Twitter

Opened 5 months ago

Closed 5 months ago

#736 closed defect (fixed)

Kernel leaks parent thread's context to children

Reported by: Jiří Zárevúcky Owned by: Jakub Jermář
Priority: blocker Milestone:
Component: helenos/kernel/generic Version: mainline
Keywords: Cc:
Blocker for: Depends on:
See also:

Description

When creating a new thread, the kernel uses context_save() followed by context_set() to create the new thread's context. This results in the child thread inheriting a significant portion of the parent's context, including between different tasks, and from kernel to userspace.

Beyond the obvious security implications, having garbage in registers makes it harder to pass meaningful arguments from loader to the loaded program.

Change History (1)

comment:1 Changed 5 months ago by Jakub Jermář

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.