Conversation

RE: https://infosec.exchange/@alleleintel/115407137517725991

My first patches landed in the Linux kernel. They are fixes for two NULL pointer dereferences (in TCP and fanotify) and a potential out-of-bounds write in the Btrfs subsystem. The latter bug was introduced about 17 years ago, and I was glad to find it. It was classified as a potential vulnerability because, given the complexity of the VFS, I wasn't able to trigger it under normal circumstances. I've found many minor issues while navigating the entrails of the Linux kernel. We will be contributing more to the Linux kernel from now on.

Ah, I've contributed not only to the Linux kernel. I also reported to the 'crash' tool developers that some commands were not working as expected on recent Linux kernel versions. Coincidentally, Fedora was providing a 'crash' tool version that had that bug at least on Fedora 42, and I also reported this. I have just received a reply saying a new version is available that does not have those bugs.

I use the 'crash' tool to teach memory management in my training, and I am also using it to write a blog post that shows some page table tricks.

https://bugzilla.redhat.com/show_bug.cgi?id=2401433

https://crash-utility.github.io/changelog/ChangeLog-9.0.0.txt

https://bodhi.fedoraproject.org/updates/FEDORA-2025-21b24d0a02

0
0
1
@andersonc0d3 congrats! Good to see bugfixes with the reporting.

RE: https://infosec.exchange/@andersonc0d3/115419629407280002
1
0
1