Comment on Passing nothing is surprisingly difficultparentComments−deathanatos2ySecurity researchers are crafty. I wouldn't give them a read-only page, either. They'll find a way to turn a null-deref with that into an exploit."And then we just look for the UID under this NULL pointer — and hey, that's a read-only page of zeros! We're now root." Or something.
Comments
Security researchers are crafty. I wouldn't give them a read-only page, either. They'll find a way to turn a null-deref with that into an exploit.
"And then we just look for the UID under this NULL pointer — and hey, that's a read-only page of zeros! We're now root." Or something.