<?xml version="1.0" encoding="UTF-8"?>

<rdf:RDF 
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns="http://purl.org/rss/1.0/"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:syn="http://purl.org/rss/1.0/modules/syndication/"
>

  <channel rdf:about="http://lwn.net/headlines/330866/">
    <title>LWN: Comments on "Linux ASLR vulnerabilities"</title>
    <link>http://lwn.net/Articles/330866/</link>
    <description>
This is a special feed containing comments posted
to the individual LWN article titled &quot;Linux ASLR vulnerabilities&quot;.

    </description>

    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>2</syn:updateFrequency>
    <items>
      <rdf:Seq>
	<rdf:li resource="http://lwn.net/Articles/331440/rss" />
	<rdf:li resource="http://lwn.net/Articles/331316/rss" />
	<rdf:li resource="http://lwn.net/Articles/331315/rss" />
	<rdf:li resource="http://lwn.net/Articles/331311/rss" />
	<rdf:li resource="http://lwn.net/Articles/331275/rss" />
	<rdf:li resource="http://lwn.net/Articles/331011/rss" />
	<rdf:li resource="http://lwn.net/Articles/330962/rss" />
	<rdf:li resource="http://lwn.net/Articles/330916/rss" />
      
      </rdf:Seq>
    </items>

  </channel>
    <item rdf:about="http://lwn.net/Articles/331440/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331440/rss</link>
      <dc:date>2009-05-03T23:12:01+00:00</dc:date>
      <dc:creator>jamesmrh</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
I can't see if there's any CC's on that email, but I suggest making sure it's cc'd to the LSM list, as well as known x86/platform experts such as Arjan, Ingo, Alan Cox, Roland McGrath etc.&lt;br&gt;
&lt;p&gt;
(I didn't even know that'd been posted until I read this thread on LWN).&lt;br&gt;
&lt;p&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/331316/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331316/rss</link>
      <dc:date>2009-05-02T13:54:57+00:00</dc:date>
      <dc:creator>willezurmacht</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
CC the -mm maintainer if you don't get lucky in the second chance. Sometimes it helps.&lt;br&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/331315/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331315/rss</link>
      <dc:date>2009-05-02T13:39:08+00:00</dc:date>
      <dc:creator>jake</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
&lt;font class=&quot;QuotedText&quot;&gt;&amp;gt; Are you aware of any progress in getting the vulnerability fixed?&lt;/font&gt;&lt;br&gt;
&lt;p&gt;
Nope.  I will resend the patch in a day or two if I don't hear anything.&lt;br&gt;
&lt;p&gt;
jake&lt;br&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/331311/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331311/rss</link>
      <dc:date>2009-05-02T13:15:38+00:00</dc:date>
      <dc:creator>willezurmacht</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
The problem with blacklisting is that you never know when your blacklist is enough. The question is if there are any true legitimate uses of this and what's specifically required.&lt;br&gt;
&lt;p&gt;
Either way, there are plenty of other methods to get around the difficulties presented by ASLR as of its current implementation in mainline kernel.&lt;br&gt;
&lt;p&gt;
I would like to know if Jake's patch goes through, hopefully it does.&lt;br&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/331275/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331275/rss</link>
      <dc:date>2009-05-02T01:37:57+00:00</dc:date>
      <dc:creator>spender</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
Hi Jake,&lt;br&gt;
&lt;p&gt;
I noticed you submitted the following patch to LKML earlier this week:&lt;br&gt;
&lt;a href=&quot;http://lkml.org/lkml/2009/4/30/265?h1=4d3afeb44daf01af97a0b9c725dcaf1453b7886c&amp;amp;h2=c1efa214c08fa9819a71f7e09815c7910f9a879b&quot;&gt;http://lkml.org/lkml/2009/4/30/265?h1=4d3afeb44daf01af97a...&lt;/a&gt;&lt;br&gt;
&lt;p&gt;
but it hasn't received any responses yet, and I haven't seen any patches submitted by anyone else.  Are you aware of any progress in getting the vulnerability fixed?&lt;br&gt;
&lt;p&gt;
-Brad&lt;br&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/331011/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/331011/rss</link>
      <dc:date>2009-04-30T16:34:39+00:00</dc:date>
      <dc:creator>nix</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
Oh that first one is quite nasty. We can stop reporting wchan for non-self users when non-root without breaking too much, but doing the same for /proc/*/stat is out of the question. Perhaps we can blank out just the sensitive fields in such cases?&lt;br&gt;
&lt;p&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/330962/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/330962/rss</link>
      <dc:date>2009-04-30T10:46:47+00:00</dc:date>
      <dc:creator>njd27</dc:creator>
      <description>
      &lt;div class=&quot;FormattedComment&quot;&gt;
Nonsense, the important question is, should the singular of &quot;jiffies&quot; be &quot;jiffie&quot; or &quot;jiffy&quot;?&lt;br&gt;
&lt;/div&gt;

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/330916/rss">
      <title>Linux ASLR vulnerabilities</title>
      <link>http://lwn.net/Articles/330916/rss</link>
      <dc:date>2009-04-30T02:32:07+00:00</dc:date>
      <dc:creator>jreiser</dc:creator>
      <description>
      &lt;i&gt;it would be a tragedy to think that known vulnerabilities are just falling through the cracks&lt;/i&gt;
&lt;p&gt;Oh, stop being so melodramatic.  It's not a tragedy.  It's money being made by those who look and listen carefully, widely, and with patience.  It was ever thus.  The important questions are the quantifiers: &quot;&lt;i&gt;How much&lt;/i&gt; money, &lt;i&gt;how often&lt;/i&gt;, &lt;i&gt;by whom&lt;/i&gt;, ...?&quot;
      
      </description>
    </item>
</rdf:RDF>

