GNU bug report logs - #26227
grep critical local DoS from userspace

Previous Next

Package: grep;

Reported by: bloodman <at> gmail.com

Date: Thu, 23 Mar 2017 19:43:01 UTC

Severity: normal

Done: Jim Meyering <jim <at> meyering.net>

Bug is archived. No further changes may be made.

Full log


Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):

From: bloodman <at> gmail.com
To: bug-grep <at> gnu.org
Subject: grep critical local DoS from userspace
Date: Thu, 23 Mar 2017 20:11:58 +0100
Hello,

Today I searched some files and... my server goes to hell (crash).

replication:

0. log into root or user account (whatever)
1. make a huge empty file (eg. 10 GB of zeros)
(my is: -rw-r--r-- 1 root root 10485760000 Feb 28 18:14 testfile.out)
2. grep -Hi "\/tmp\/" * 2>/dev/null
3. crash (probably due to out of memory)

... damn...

greetz,
-- 
Tomasz 'BloodMan' Tomkowiak





This bug report was last modified 8 years and 56 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.