Found bugs
Most latest bugs are reported by syzbot to syzkaller-openbsd-bugs mailing list and are listed on the dashboard.
Newer bugs comes first.
-
shmat: propagate error instead of panicking on allocation failure
-
pf(4): incorrect handling of overlapping fragments ERRATA-68-014
-
pf(4):
pfsync_state_import()
cannot be called with the pf state lock held -
sosplice(9): stack overflow while handling broadcast packets
-
unveil: do not increment
ps_uvncount
more than once per unveiled path -
ip6(4): don’t use the flow of the first fragment to store ECN data
-
recv: unexpected mbuf queue growth while sleeping ERRATA-64-009
-
getsockopt: errorneous switch fall through in
rip_usrreq()
affecting many socket related syscalls -
shutdown: integer overflow in
unp_internalize()
ERRATA-64-006 -
poll: execution of address
0x0
caused by console redirection -
open: NULL pointer dereference while operating on cloned device
-
fchown: NULL pointer dereference while operating on cloned device
-
ftruncate: NULL pointer dereference while operating on cloned device
原文链接: https://github.com/google/syzkaller/blob/master/docs/openbsd/found_bugs.md
选题: jxlpzqc
本文将由 HCTT 翻译团队 原创翻译,华中科技大学开放原子开源俱乐部荣誉推出。