From owner-cvs-all Mon May 10 11: 9:43 1999 Delivered-To: cvs-all@freebsd.org Received: from freefall.freebsd.org (freefall.FreeBSD.ORG [204.216.27.21]) by hub.freebsd.org (Postfix) with ESMTP id C0AE615DF1; Mon, 10 May 1999 11:09:41 -0700 (PDT) (envelope-from truckman@FreeBSD.org) Received: (from truckman@localhost) by freefall.freebsd.org (8.9.3/8.9.2) id LAA28740; Mon, 10 May 1999 11:09:41 -0700 (PDT) (envelope-from truckman@FreeBSD.org) Message-Id: <199905101809.LAA28740@freefall.freebsd.org> From: Don Lewis Date: Mon, 10 May 1999 11:09:41 -0700 (PDT) To: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: src/sys/kern uipc_usrreq.c Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk truckman 1999/05/10 11:09:41 PDT Modified files: sys/kern uipc_usrreq.c Log: Fix descriptor leak provoked by KKIS.05051999.003b exploit code. unp_internalize() takes a reference to the descriptor. If the send fails after unp_internalize(), the control mbuf would be freed ophaning the reference. Tested in -CURRENT by: Pierre Beyssac Revision Changes Path 1.44 +4 -1 src/sys/kern/uipc_usrreq.c To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message