• Linus Torvalds's avatar
    Merge tag 'hardening-v6.1-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/kees/linux · d0989d01
    Linus Torvalds authored
    Pull kernel hardening updates from Kees Cook:
     "Most of the collected changes here are fixes across the tree for
      various hardening features (details noted below).
    
      The most notable new feature here is the addition of the memcpy()
      overflow warning (under CONFIG_FORTIFY_SOURCE), which is the next step
      on the path to killing the common class of "trivially detectable"
      buffer overflow conditions (i.e. on arrays with sizes known at compile
      time) that have resulted in many exploitable vulnerabilities over the
      years (e.g. BleedingTooth).
    
      This feature is expected to still have some undiscovered false
      positives. It's been in -next for a full development cycle and all the
      reported false positives have been fixed in their respective trees.
      All the known-bad code patterns we could find with Coccinelle are also
      either fixed in their respective trees or in flight.
    
      The commit message in commit 54d9469b...
    d0989d01
Makefile 69.5 KB