From owner-freebsd-security@FreeBSD.ORG Sun Jun 18 20:10:08 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C486416A47F for ; Sun, 18 Jun 2006 20:10:08 +0000 (UTC) (envelope-from neiro21@gmail.com) Received: from py-out-1112.google.com (py-out-1112.google.com [64.233.166.179]) by mx1.FreeBSD.org (Postfix) with ESMTP id EB3D643D6B for ; Sun, 18 Jun 2006 20:09:59 +0000 (GMT) (envelope-from neiro21@gmail.com) Received: by py-out-1112.google.com with SMTP id e30so1105465pya for ; Sun, 18 Jun 2006 13:09:57 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=HWdiBRWWt614MHqOTEgtcY5BOH6zbl27P+iIvOXWJc8qDdooUVBuUE+ZLZLQo55uApTFOPISNZGqDW0ztZExBT4UlE1UbBRU4t6mRjKsZs1yo+v/AHDVeT9pFbRRQp/eKK4DQfRmb0WoAGkgKmDgf5qKym0KY72ezZJa9ZPm104= Received: by 10.35.14.1 with SMTP id r1mr7424712pyi; Sun, 18 Jun 2006 13:09:57 -0700 (PDT) Received: by 10.35.125.6 with HTTP; Sun, 18 Jun 2006 13:09:57 -0700 (PDT) Message-ID: <3bcb4e3f0606181309h70c08dc6l691bbb6e5b48615a@mail.gmail.com> Date: Mon, 19 Jun 2006 00:09:57 +0400 From: "Nick Borisov" To: "=?ISO-8859-1?Q?Dag-Erling_Sm=F8rgrav?=" , freebsd-security@freebsd.org In-Reply-To: <86odwqs71f.fsf@xps.des.no> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <3bcb4e3f0606180056o63424cc0g5c121443e45fa333@mail.gmail.com> <3bcb4e3f0606180127m3c4fdb13n2b42deb881b7bdc6@mail.gmail.com> <86odwqs71f.fsf@xps.des.no> Cc: Subject: Re: memory pages nulling when releasing X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 18 Jun 2006 20:10:08 -0000 2006/6/18, Dag-Erling Sm=F8rgrav : > "Nick Borisov" writes: > > Could you tell me if FreeBSD supports memory page nulling when > > releasing it to prevent unauthorized access to data left in the page > > after it's allocated again. > > Processes always get zeroed pages from the kernel. This is the case > for all Unices, and has been for decades. Well, providing zeroed pages to processes is not quite similar to explicit cleaning of pages after use as some security standards demand. That's why I'm asking. The "Z" malloc option seems to be suitable but it's actually for debugging.