This doesn't seem true from the commit: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
The bug is said to not be exploitable since Al Viro function change. This change happened in 3.19.
The bug is said to not be exploitable since Al Viro function change. This change happened in 3.19.
http://lxr.free-electrons.com/source/net/core/datagram.c?v=3...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
I am just trying to completely understand the bug, I wonder if it really was unexploitable before the patch. Got any source for that?
EDIT: sorry, misunderstood your message / mixed up commits, I was looking into when 89c22d8c3b27 hit mainline, which causes the vulnerable code path.