From linux-mm-bugs-bounce@nl.linux.org Tue Feb 03 13:14:33 2004
Received: from localhost.nl.linux.org ([127.0.0.1] helo=humbolt.)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1AnzRb-0002DE-DR; Tue, 03 Feb 2004 13:14:19 +0100
Received: with LISTAR (v1.0.0; list linux-mm-bugs); Tue, 03 Feb 2004 13:14:18 +0100 (CET)
Received: from web20406.mail.yahoo.com ([66.163.169.94] helo=web20418.mail.yahoo.com)
	by humbolt.nl.linux.org with smtp (Exim 4.22)
	id 1AnzQA-0001ww-De
	for linux-mm-bugs@nl.linux.org; Tue, 03 Feb 2004 13:12:50 +0100
Message-ID: <20040203121241.19663.qmail@web20418.mail.yahoo.com>
Received: from [211.106.35.86] by web20406.mail.yahoo.com via HTTP; Tue, 03 Feb 2004 21:12:41 JST
Date: Tue, 3 Feb 2004 21:12:41 +0900 (JST)
From: =?euc-kr?q?byeung=20oh?= <lccobok@yahoo.co.kr>
Subject: Medicine rescue(forum)&Diagnosis 
To: linux-mm-bugs@nl.linux.org
MIME-Version: 1.0
Content-Type: text/plain; charset=euc-kr
Content-Transfer-Encoding: 8bit
Received-SPF: humbolt: domain of lccobok@yahoo.co.kr does not designate permitted sender hosts
X-Spam-Checker-Version: SpamAssassin 2.60-spambr_20030926 
	(1.212-2003-09-23-exp) on humbolt.nl.linux.org
X-Spam-Status: No, hits=2.1 required=5.0 tests=BAYES_90 autolearn=ham 
	version=2.60-spambr_20030926
X-Spam-Level: **
X-listar-version: Listar v1.0.0
Sender: linux-mm-bugs-bounce@nl.linux.org
Errors-to: linux-mm-bugs-bounce@nl.linux.org
X-original-sender: lccobok@yahoo.co.kr
Precedence: bulk
Reply-to: linux-mm-bugs@nl.linux.org
List-help: <mailto:listar@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-mm-bugs-request@nl.linux.org?Subject=unsubscribe>
List-software: Listar version 1.0.0
X-List-ID: <linux-mm-bugs.nl.linux.org>
List-subscribe: <mailto:linux-mm-bugs-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:riel@nl.linux.org>
List-post: <mailto:linux-mm-bugs@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-mm-bugs/>
X-list: linux-mm-bugs

I pray your eternal development.
I wish to develop New Millennium of that is paradigm
within change,
in medical treatment field new health medical
examination 
and treatment and contribute in mankind health by
commercial development.
I desire to participate to investment consortium with
submitted.
Thank you.
submitted;Forum
======================================================

Medical treatment strong young man for healthy life
     (Sundry medicines nullity it is hoop that can buy
a little more healthfully¡¦)
======================================================

L.C.C. Life environment research institute 
  Byeungok Oh
 (Lccobok@yahoo.co.kr)


Until life reverence in daily affairs by wonder of
life
Until donate of oneself own recovery from accept of
sacrifice unlimitedly
DNA and penance interval that is difficult to achieve
that recognize own reproduction
That to want to convey but appear without being
transmissive had been vague 
Although impression that old wise mans' impatience
gets cut goes first

I am going to propose new medical treatment and
medical examination and treatment along with new
century boldly. I had been studying new medical
treatment medical examination and treatment method for
a long time. By the way, present medical treatment
medical examination and treatment direction is added
confusion in limit situation. It is best expedient
that modern medical treatment method removes part that
becomes an issue, it is not escaping alternation or
classic treatment (antibiosis several use) level by
surgical operation putting first. There are no drug
stuffs that there is no side effect in restriction
field.

Aspirin that there is no side effect almost According
to each single person, different result appears. But,
the medicines development by recent gene arrangement
analysis has much controversial points if consider
economic performance and efficiency although is
foreseen that is good perfume
More medical treatment medical examination and
treatment direction must consider living body molecule
surrounding than what Being going out by analysis
putting first DNA rescue, gene arrangement analysis
etc. Because system concept that is keeping function
is lacking, administration is not becoming entirely. 
 So, as it have exchanged the parts if it become an
issue in high grade semi-conductor 
That human body has changed part that becomes an
issue, being attempting attempt to destroy essence of
life. Arrive by own ruin that is suicide site process
clearly even if try doing not know
It can classify roughly disease of human body of
mental disease (lewdness sex, violence), circulatory
system (heart), engine (surely, hlycosuria),
retrogression (joint) disease etc . It is going to
diagnose and must prevent change is basic human body
on gene constituent, is coping change state as
negative circumscriptively.
So, it has been disappeared to human body, formation
agency's own protection and defense function Human
body is not controlling normal energy level being
esteemed nutrient excess state arriving at present
age. If it can diagnose, but appear by disease
syndrome once that is lack of exercise, while optimum
energy level of human body is such to arrive in low
point, medical examination and treatment behavior
aggravates situation. Talk living body replace backup
that thing which cultivate stem cell by purpose is
desirable, but esteemed nutrient supply system is
misreckoning in cell state energy and energy status
gets into very lacking status as human body
organization. Although BT field that advanced nations
are gene therapy putting first speaks as New
Technology, this commits self-contradiction and is not
formed as mechanical.

So, LCC life environment research institute is
establishing human body dialogue energy system to new
living body system concept and examine closely energy
essence. Human body is eased to require much energy
and lose balance equilibrium gradually effectively
therefore, it is been in step that all energy circles
are changed in order for activation energy. Then,
method to prevent change must supply enough energy,
with food or nutritive substance, drug stuffs dialogue
or ATP-energy system is lacking to energy system, and
exercise method is no efficiency, and life environment
system is need efficiently. But, dwindle that
conversation is impossible by culture aspect
difference ago disease treatment up to now do. 

Then, if investigate essence of energy of priority
life environment system
Energy creation by esteemed nutrient supply is spent
in several forms by human body activation energy
usually in human body. This energy is activation
energy. By the way, there is energy state of molecule
level that serve to keep human body formation, is high
more than sub energy level is activate state and is
static energy system.
In activation energy human body all organ
preservations and activation energy necessity be
supplied adequately and is consumed. If it has been
changed to state and has been spent is static energy
at time that is imbalance state or is lacking,
recovery charge is very difficult again

Because energy level of molecule level is higher than
existing energy system. If this vicious circle is
repeated, cell molecule state raises energy change
from neighborhood molecule cell function becomes weak
and get back. This phenomenon is apt to be developed
by various disease syndromes. 
Usually, energy level of nutritive substance becomes
lower than sub-level is static energy.  So, there is
case that supplies necessity nutritive substance while
center energy by strong stimulation in weak region of
human body institutively, but is very rare sub-level
of that efficiency of antibiosis emperor or vaccine
etc.
Drops separates and is because absolute difference
energy level becomes similar is human body energy
constantly. So, human body immunity does not defend
enough about cause material such as virus from
outside. Usually, outside environment energy is high
more than human body interior environment energy. If
it is not this state, human body needs protector

If sort energy system
ATP-energy creation that is created in mitochondria
and save system: E1
Outside environment energy exchange that is created in
lung and storing accumulation system: E2
        E1 < E2: Stationary state
        E1 > E2: Non-reaction state, Cultivation and
reproduction incongruence state
        E1 Function: Creation save
        E2 Function: Exchange and part storing
accumulation
        E2 Supply method: Nutritive substance and food
        E1 Supply method: Outside environment
        | E2 - E1 |: Level difference is absolute
energy
And strong part and weak part of human body are
coexisted locally seasonally. 
Human body should be supplied energy from outside by
such basic concept, Age of human body outside
environment passes, and environment state becomes very
inferior
Also, it cannot but be ephemeral although treatment
method by gene engineering etc. Is presented. Then, is
escaping even discussion up to now supplying enough
normal energy to escape treatment limit. 
Then, it is covenant development by gene arrangement
analysis or organ principal parts by stem cell
cultivation the best model of treatment? It must try
inquiry.

Human body is weak continuously, but culture for
function repletion is developing great on the
contrary. So, characteristics that can be classified
roughly particularly the second industry age the first
industry age enumeration be possible, and therefore is
that human body becomes very weak basically.
Equip special environment system for this effect
although outside environment and esteemed daughter
supply system such as the first industry age will need
specially for normal energy system interested person
of human body conclusively. It can contribute newly
mankind health and disease prevention to these method
and concept.
First of all, main target must prevent energy change
in human body establishment.
Living body organization which function is suspended
deducts when it cannot but remove but it is suspended
to cause by worst situation before, it must recover
function change energy supply system. So, medical
examination field can take a serious view and present
gene analysis etc. There are developing, but they have
hasty conclusion to tell so that alternate
organization to watch eagerly. It is focused in
special quality for immune body elevation in drug
field but it is helpless in formation function
enfeeblement prevention. There is reaction equilibrium
point by great many dialogue effect in human body
therefore, there is apt to be energy level. Because
human body is consuming energy for function
preservation, there is no worry to become inverse
reaction
Also, in high energy level, energy if have been
discharged charge very difficult
Because energy level of this static energy system is
high than activation energy system sub-officer, so,
static energy level fixed extent that is, is
activation energy when is normal state dialogue state
Although increase by straight line style according to
momentum or decrease It is changed in absurd energy
change form outside sub-officer extent is static
energy. By the way, side effect becomes serious as for
drug stuffs.

As it were, excess energy is consumed to organization
which energy level is lower 
It does not reach in energy level of part that become
an issue. General esteemed nutrient supply is not
gotten back. So, although drug stuffs that is combined
with particular enzyme can be valid also, it do not
stop side effect problem. So, although it does that
food and particular medicines get effect that is
special 
It cannot avoid much damage that is side effects. 
Some basis items should be prepared before disease
treatment 
If it sees expected phenomenon
Q1) Understand essence is metabolgy and should be
systematized and is energy administration available?
A1) Is coping partially Synthetic judgment there is no
and is wholly lacking even concept altogether.

Q2) Immune body and formation function enfeeblement
are led at the same time 
Can minimize side effect of drug stuffs?
A2) Got absolute effect of drug stuffs at early Go,
need more strong drug stuffs 
It cannot avoid excess use and side effect is
accompanied.

Q3) Human anatomy state according to energy path
transfer infinite variety change 
Can foretell to be treatment timely and diagnosis
time?
A3) Dropping most time Minuteness diagnosis system
amounts divide currency
 Whenever need, because diagnose again minuteness
diagnosis system is required ordinary times
Accompanied diagnosis expense is high price. 
By the way, is very important to be treatment.

Q4) Sundry medicines are paralyzed and are coped in
disease end symptoms?
A4) Countermeasure there is no and undergoes different
case religious treatment.

Q5) The human body formation agency function for
disease factor enfeeblement or action if is
degenerated what be?
A5) It is alternating by special skill that it is no
formation refusal reaction.

Q6) Do you have countermeasure in Gene factor's
disease?
A6) Cause and treatment process are proceeded
individually

Q7) If is diagnosed by gork, can lay countermeasure?
A7) Even if is euthanasia, is in special skill
donation trend.

If question and situation of reply are caused so, get
into medical examination and
treatment limit situation. Then, as example model of
medical examination and treatment

If diagnose Harvard university (Harvard university
diagnosis)
Add that is applied first to universal superior
colleges more than a specification university. Tried
but was cool all to improve medical examination and
treatment using life environment special procurements
equipment for a long time
So, it is going to apply Harvard University
concentrically at Monitoring All fields are exposed in
limit situation lifting new 21th century. If recognize
fast and do not cope this, is caused in abyss of
disorder. It does not reach in fundamental solution
although all informations are operated efficiently
through internet medium.
Is going to examine closely So, in genome project,
fundamental problem of genetic engineering field
human, but go back to bioethics preferably.

In American building special quality synthesis
function exhaustively the building military be rising
but is not approaching in basic problem solution of
life. Environment of culture that develops by party¡¯s
putting first and function putting first commonly
cannot seek some countermeasure. Human desire becomes
that contributed in clear mankind health in industry
age in medical treatment field, but it is not
presenting any countermeasure because coming at now.
It is connoting many problems in the most fundamental
dietary life. Energy by pollution is eating food that
is not enough by human.
As is doing and try gene transformation, is
aggravating situation preferably. With various kinds
problem at the human body by disease syndrome is
4field great classify .
Of course, forward, although there is necessity to
define little more correct classification standard Of
retrogression disease digestive system, arthritis etc.
with net ventilation system, surely, hlycosuria with
mind system disease, heart
After classify Problem is drawn spontaneously
commonly. Though human body organized by superior
synthesis function, by area, custom, hereditary nature
etc. 
Some a part becomes disablement and is appeared by
disease syndrome. But, human body is superior itself
recovery ability Preferably, make to difficult
environment of drug stuffs abuse Innumerable medicines
are developed so far, but there is no medicine that is
not virus 

If apply problem little more concretely
Harvard University is no tradition as distinguished
family and inferiority as universal college. Meet
hereupon students¡¯ 24 hours work and life by daily
work that get into pressure during 35 hours studies do
.So, finishing some formally process excellently
It has become very impotently to handle nonformula one
in spot ultimately.
There is no creative mind, and leader ship there is no
and is adapted in environment that is given only. If
this phenomenon becomes accumulation, Harvard may have
plunged in chaos of disorder Then, by solution, if
present
Because do body fluids analysis of blood, urea
analysis etc. at the all students, must draw common
factor. Analyze so tolerance limit numerical value to
be overcome environment treatment receive must.
Otherwise, a student fewer than tolerance limit
numerical value becomes individually very
unfortunately. Expressed by individual here, but if do
sampling in population, 10% is existed. So, it can be
predicted easily that is changed by some disease
syndrome. Although speak that is superior even if
brain uses 10%. Energy system that follow hereupon
because is limitative by specialized field resects
must. So, if apply environment treatment system
Human must be supplied energy during all life and is
consuming energy constantly
Because energy utilization efficiency is low to food
or nutritive substance more than much serious
metabolgy is caused also, human body energy principle
becomes nutritive substance intake hardly in low
energy state .So, as part of repletion
Must take advantage of photosynthesis function
although human body is no photosynthesis function as
vegetable field. It can treat systematizing this, 
Treatment is available on powerless part of energy
supply efficiency 250% other weak human bodies. There
is no materialistic system present and there is no
common use changed thing think all abstractly and
avoid,
There is no interest altogether beside own field and
there is no any countermeasure.
And first of all, although energy mechanism is applied
being examined closely well
Energy real and quantitative management are not
achieved. Because had been used within life more than
mankind life centuries, it is that systematize this
developing with monitor ring only. Because had used Of
course, mankind is centuries directly although speak
that presence at a sickbed verification test will need
interval Presence at a sickbed and virulent problem
solved naturally Establishment condition is kept along
with here and environment prevention of pollution
condition to follow at computer life else - it is
basic countermeasure for E- thrombus certificate
Although East does to get something through special
procurements exercise such as yoga It is trying
without appearing concretely. 
As the example, when is cancer
If grow because cancer happens to magnetic pole with
various kinds factor, the state is gone very fast.
Although it is best method that remove relevant region
present
It is evidence that energy is lacking that is grown
and is changed. But, there is no method that supply
enough energy Efficiency is low food and drug stuffs
energy mechanism and route well does not prescribe .It
can not but depend on itself energy supply means only
This is aggravating more situation. So, it gets into
station reaction state if supply energy that enough
efficiency is high Change state stops and cell is
gotten back normally. Also, thing that nitrogen
monoxide mechanism is very important in heart disease
Nobel medically According as is authorized 
Directly environment system treatment possibility gets
worn out.
First of all, all problems that follow in smoking are
become countermeasure perfectly
Although recently many research organizations such as
NIH proposed 
Expression insufficiency or lack of understanding
continuously forefinger altogether access does not
become .So, solve fundamental problem of Harvard
university laying stress on connection research
institute It can compose synthetic environment
treatment system forming consiotium10billon$.
Although can speak that this capital scale is big As
the example, comparison does not become compared to
damage sum production by smoking of factor of disease.
That do people health promotion by purpose by
endowment and way of support as for other method
hospital new construction is sound. So, it is subject
that is contributed in mankind health promotion by new
medical treatment improvement.  End.
 =====================================================

Diagnosis (1)


L.C.C. Life environment research institute 
 Byeungok Oh
 (Lccobok@yahoo.co.kr)


Does more than various disease recognize to warning
message of age?
As disease of respiratory system, transformation virus
by Sars, bad cold immune body of human body becomes
powerless , Damage becomes remarkably. 
Though confrontation immunity element is broken, there
is no preventive method here.
So, survival immunity time of human body is not long.

It is foreseen to this becomes ecosystem
transformation by development of life culture and
damage is connected to greate disaster as throng life
form. 
Also, syndrome more than disease that happen to the
domestic animalses with mad-cow disease, foots disease
etc.. is been caused most domestic animals castle
equipment environments and foods material, but is
becoming serious problem as is fed for direction
controlled mostly to be prevented by animal survival
instinct.
 End, is proportional and is not regulating medium
here because number of individual is so much.
Time did not remain little if is going to leave
continuously
Red signal is lighted in mankind health care
gradually.
It must change mode of life to culture originally in
function putting first culture as quickly as possible.
Human body function preservation energy system is
becoming disablement gradually.
Is going to be seeking incidental long-term part
replacement or gene therapy perfectly and hang down to
existing treatment method ?
Still, life environment intensive care should be been
prior if want to be healthy
So, one by one mode of life originally by foundation
kind be gotten back and must accomplish creation

Therefore, sort main field
¡à Because information is converged, human body
confrontation field according as work and convergence
are become very high

¡à Food, processed food that is deformed gene is
energy supply system field though energy supply of
schedule level is led

¡à Field that treatment that demobilize priority
mother's body because it is no efficiency if done
treatment medicines go unique immunity but immune body
becomes low relatively must precede standardization

¡à Field that must undergo gradually life environment
treatment by diagnosis by a paperweight ticket
sensitivity than human body minuteness diagnosis
expense
¥É step : Cycle environment treatment (most patient)
of respiratory system
¥É¥É step : Environment treatment (end patients) by
hemodialysis same time

¡à In necessary industry energy field in function
putting first culture system ecosystem balance lose
principal parts field that follow hereupon

It must cope forward.
Thus noninterference if it is done in circulation of
nature be driven out .   End .                        
                                          










_____________________________________________________________________
¿¹»Û ÆíÁöÁö¿¡ ¸ÞÀÏÀ» º¸³»¼¼¿ä - ¾ßÈÄ! ¸ÞÀÏ
http://mail.yahoo.co.kr
½ÅÂ÷,Áß°íÂ÷,Á÷°Å·¡ ¸Å¹°ÀÌ ÇÑÀÚ¸®¿¡ - ¾ßÈÄ! ÀÚµ¿Â÷
http://autos.yahoo.co.kr/autos/

--
Linux-mm-bugs:  bugzilla list for the Linux-MM subsystem
Archive:        http://mail.nl.linux.org/linux-mm-bugs/
Web site:       http://linux-mm.org/
Development:    linux-mm@kvack.org



From linux-mm-bugs-bounce@nl.linux.org Wed Feb 18 15:41:59 2004
Received: from localhost.nl.linux.org ([127.0.0.1] helo=humbolt.)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1AtStS-0000S8-HE; Wed, 18 Feb 2004 15:41:42 +0100
Received: with LISTAR (v1.0.0; list linux-mm-bugs); Wed, 18 Feb 2004 15:41:41 +0100 (CET)
Received: from distro2.conectiva.com.br ([200.140.247.104])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1AtSsY-0000JP-C7
	for linux-mm-bugs@nl.linux.org; Wed, 18 Feb 2004 15:40:46 +0100
Received: by distro2.conectiva.com.br (Postfix, from userid 101)
	id 21432702A; Wed, 18 Feb 2004 11:40:30 -0300 (BRT)
From: bugzilla-daemon@distro2.conectiva.com.br
To: linux-mm-bugs@nl.linux.org
Subject: [Bug 10776] New: bug.. vc jah devem saber mas em todo caso...
X-Bugzilla-Reason: AssignedTo
Message-Id: <20040218144030.21432702A@distro2.conectiva.com.br>
Date: Wed, 18 Feb 2004 11:40:30 -0300 (BRT)
Received-SPF: humbolt: domain of www@distro2.conectiva.com.br does not designate permitted sender hosts
X-Spam-Checker-Version: SpamAssassin 2.60-spambr_20030926 
	(1.212-2003-09-23-exp) on humbolt.nl.linux.org
X-Spam-Status: No, hits=0.2 required=5.0 tests=NO_REAL_NAME autolearn=no 
	version=2.60-spambr_20030926
X-Spam-Level: 
X-listar-version: Listar v1.0.0
Sender: linux-mm-bugs-bounce@nl.linux.org
Errors-to: linux-mm-bugs-bounce@nl.linux.org
X-original-sender: bugzilla-daemon@distro2.conectiva.com.br
Precedence: bulk
Reply-to: linux-mm-bugs@nl.linux.org
List-help: <mailto:listar@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-mm-bugs-request@nl.linux.org?Subject=unsubscribe>
List-software: Listar version 1.0.0
X-List-ID: <linux-mm-bugs.nl.linux.org>
List-subscribe: <mailto:linux-mm-bugs-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:riel@nl.linux.org>
List-post: <mailto:linux-mm-bugs@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-mm-bugs/>
X-list: linux-mm-bugs

  #############################################################
  # DO NOT RESPOND TO THIS EMAIL  # NAO RESPONDA A ESTE EMAIL #
  # USE THE WEB INTERFACE INSTEAD # USE A INTERFACE WEB       #
  #############################################################



http://bugzilla.conectiva.com.br/show_bug.cgi?id=10776

           Summary: bug.. vc jah devem saber mas em todo caso...
           Product: Linux kernel MM
           Version: 2.4 (stable)
          Platform: Other
        OS/Version: Linux
            Status: UNCONFIRMED
          Severity: major
          Priority: P1
         Component: linux mm
        AssignedTo: linux-mm-bugs@nl.linux.org
        ReportedBy: smyows@yahoo.com.br


Synopsis:  Linux kernel do_mremap VMA limit local privilege escalation 
           vulnerability 
Product:   Linux kernel 
Version:   2.2 up to 2.2.25, 2.4 up to 2.4.24, 2.6 up to 2.6.2 
Vendor:    http://www.kernel.org/ 
URL:       http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt 
CVE:       CAN-2004-0077 
Author:    Paul Starzetz <ihaquer@isec.pl> 
Date:      February 18, 2004 
 
 
Issue: 
====== 
 
A critical security vulnerability has been found in the Linux kernel  
memory management code inside the mremap(2) system call due to missing  
function return value check. This bug is completely unrelated to the  
mremap bug disclosed on 05-01-2004 except concerning the same internal  
kernel function code. 
 
 
Details: 
======== 
 
The Linux kernel manages a list of user addressable valid memory  
locations on a per process basis. Every process owns a single linked  
list of so called virtual memory area descriptors (called from now on  
just VMAs). Every VMA describes the start of a valid memory region, its  
length and moreover various memory flags like page protection.  
 
Every VMA in the list corresponds to a part of the process's page table.  
The page table contains descriptors (in short page table entries PTEs)  
of physical memory pages seen by the process. The VMA descriptor can be  
thus understood as a high level description of a particular region of  
the process's page table storing PTE properties like page R/W flag and  
so on. 
 
The mremap() system call provides resizing (shrinking or growing) as  
well as moving of existing virtual memory areas or any of its parts  
across process's addressable space. 
 
Moving a part of the virtual memory from inside a VMA area to a new  
location requires creation of a new VMA descriptor as well as copying  
the underlying page table entries described by the VMA from the old to  
the new location in the process's page table. 
 
To accomplish this task the do_mremap code calls the do_munmap()  
internal kernel function to remove any potentially existing old memory  
mapping in the new location as well as to remove the old virtual memory  
mapping. Unfortunately the code doesn't test the return value of the  
do_munmap() function which may fail if the maximum number of available  
VMA descriptors has been exceeded. This happens if one tries to unmap  
middle part of an existing memory mapping and the process's limit on the  
number of VMAs has been reached (which is currently 65535). 
 
One of the possible situations can be illustrated with the following  
picture. The corresponding page table entries (PTEs) have been marked  
with o and x: 
 
Before mremap(): 
 
(oooooooooooooooooooooooo)     (xxxxxxxxxxxx) 
[----------VMA1----------]     [----VMA2----] 
      [REMAPPED-VMA] <---------------| 
 
 
After mremap() without VMA limit: 
 
(oooo)(xxxxxxxxxxxx)(oooo) 
[VMA3][REMAPPED-VMA][VMA4] 
 
 
After mremap() but VMA limit: 
 
(ooooxxxxxxxxxxxxxxoooo) 
[---------VMA1---------] 
     [REMAPPED-VMA] 
 
 
After the maximum number of VMAs in the process's VMA list has been  
reached do_munmap() will refuse to create the necessary VMA hole because  
it would split the original VMA in two disjoint VMA areas exceeding the  
VMA descriptor limit. 
 
Due to the missing return value check after trying to unmap the middle  
of the VMA1 (this is the first invocation of do_munmap inside do_mremap  
code) the corresponding page table entries from VMA2 are still inserted  
into the page table location described by VMA1 thus being subject to  
VMA1 page protection flags. It must be also mentioned that the original  
PTEs in the VMA1 are lost thus leaving the corresponding page frames  
unusable for ever. 
 
The kernel also tries to insert the overlapping VMA area into the VMA  
descriptor list but this fails due to further checks in the low level  
VMA manipulation code. The low level VMA list check in the 2.4 and 2.6  
kernel versions just call BUG() therefore terminating the malicious  
process. 
 
There are also two other unchecked calls to do_munmap() inside the  
do_mremap() code and we believe that the second occurrence of unchecked  
do_munmap is also exploitable. The second occurrence takes place if the  
VMA to be remapped is beeing truncated in place. Note that do_munmap can  
also fail on an exceptional low memory condition while trying to  
allocate a VMA descriptor. 
 
We were able to create a robust proof-of-concept exploit code giving  
full super-user privileges on all vulnerable kernel versions. The  
exploit code will be released next week. 
 
 
Impact: 
======= 
 
Since no special privileges are required to use the mremap(2) system  
call any process may use its unexpected behavior to disrupt the kernel  
memory management subsystem. 
 
Proper exploitation of this vulnerability leads to local privilege  
escalation giving an attacker full super-user privileges. The  
vulnerability may also lead to a denial-of-service attack on the  
available system memory. 
 
Tested and known to be vulnerable kernel versions are all <= 2.2.25, <=  
2.4.24 and <= 2.6.2. The 2.2.25 version of Linux kernel does not  
recognize the MREMAP_FIXED flag but this does not prevent the bug from  
being successfully exploited. All users are encouraged to patch all  
vulnerable systems as soon as appropriate vendor patches are released.  
There is no hotfix for this vulnerablity. Limited per user virtual  
memory still permits do_munmap() to fail. 
 
 
Credits: 
======== 
 
Paul Starzetz <ihaquer@isec.pl> has identified the vulnerability and  
performed further research. COPYING, DISTRIBUTION, AND MODIFICATION OF  
INFORMATION PRESENTED HERE IS ALLOWED ONLY WITH EXPRESS PERMISSION OF  
ONE OF THE AUTHORS. 
 
 
Disclaimer: 
=========== 
 
This document and all the information it contains are provided "as is",  
for educational purposes only, without warranty of any kind, whether  
express or implied. 
 
The authors reserve the right not to be responsible for the topicality,  
correctness, completeness or quality of the information  provided in  
this document. Liability claims regarding damage caused by the use of  
any information provided, including any kind of information which is  
incomplete or incorrect, will therefore be rejected.



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

--
Linux-mm-bugs:  bugzilla list for the Linux-MM subsystem
Archive:        http://mail.nl.linux.org/linux-mm-bugs/
Web site:       http://linux-mm.org/
Development:    linux-mm@kvack.org



From linux-mm-bugs-bounce@nl.linux.org Mon Feb 23 02:01:42 2004
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1Av2na-0006ph-OX; Mon, 23 Feb 2004 00:14:10 +0100
Received: with ECARTIS (v1.0.0; list linux-mm-bugs); Mon, 23 Feb 2004 00:14:09 +0100 (CET)
Received: from imladris.surriel.com ([66.92.77.98])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1Av20v-0002ra-Kr
	for linux-mm-bugs@nl.linux.org; Sun, 22 Feb 2004 23:23:53 +0100
Received: from distro2.conectiva.com.br ([200.140.247.104])
	by imladris.surriel.com with esmtp (Exim 4.22)
	id 1AuErY-0004Ry-Ip
	for linux-mm-bugs@nl.linux.org; Fri, 20 Feb 2004 12:54:56 -0500
Received: by distro2.conectiva.com.br (Postfix, from userid 101)
	id 56348701C; Fri, 20 Feb 2004 14:52:41 -0300 (BRT)
From: bugzilla-daemon@distro2.conectiva.com.br
To: linux-mm-bugs@nl.linux.org
Subject: [Bug 10776] bug.. vc jah devem saber mas em todo caso...
X-Bugzilla-Reason: AssignedTo
Message-Id: <20040220175241.56348701C@distro2.conectiva.com.br>
Date: Fri, 20 Feb 2004 14:52:41 -0300 (BRT)
Received-SPF: imladris: domain of www@distro2.conectiva.com.br does not designate permitted sender hosts
X-Spam-Status: No, hits=1.1 required=5.0
	tests=BUGZILLA_BUG,NO_REAL_NAME,UPPERCASE_25_50
	version=2.55
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp)
X-ecartis-version: Ecartis v1.0.0
Sender: linux-mm-bugs-bounce@nl.linux.org
Errors-to: linux-mm-bugs-bounce@nl.linux.org
X-original-sender: bugzilla-daemon@distro2.conectiva.com.br
Precedence: bulk
Reply-to: linux-mm-bugs@nl.linux.org
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-mm-bugs-request@humbolt?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-mm-bugs.humbolt>
X-List-ID: <linux-mm-bugs.humbolt>
List-subscribe: <mailto:linux-mm-bugs-request@humbolt?Subject=subscribe>
List-owner: <mailto:riel@nl.linux.org>
List-post: <mailto:linux-mm-bugs@humbolt>
List-archive: <http://mail.nl.linux.org/linux-mm-bugs/>
X-list: linux-mm-bugs

  #############################################################
  # DO NOT RESPOND TO THIS EMAIL  # NAO RESPONDA A ESTE EMAIL #
  # USE THE WEB INTERFACE INSTEAD # USE A INTERFACE WEB       #
  #############################################################



http://bugzilla.conectiva.com.br/show_bug.cgi?id=10776

andreas@conectiva.com.br changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|UNCONFIRMED                 |RESOLVED
         Resolution|                            |FIXED



------- Additional Comments From andreas@conectiva.com.br  2004-02-20 14:52 -------
Anúncio feito, fechando o ticket.
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000820



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

--
Linux-mm-bugs:  bugzilla list for the Linux-MM subsystem
Archive:        http://mail.nl.linux.org/linux-mm-bugs/
Web site:       http://linux-mm.org/
Development:    linux-mm@kvack.org



