Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1313756

[PATCH 4.3 55/55] KEYS: Fix keyring ref leak in join_session_keyring()

From Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject [PATCH 4.3 55/55] KEYS: Fix keyring ref leak in join_session_keyring()
Date 2016-01-21 01:50 +0100
Message-ID <qTbBN-5Oq-53@gated-at.bofh.it> (permalink)
References <qTbBL-5Oq-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


4.3-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yevgeny Pats <yevgeny@perception-point.io>

commit 23567fd052a9abb6d67fe8e7a9ccdd9800a540f2 upstream.

This fixes CVE-2016-0728.

If a thread is asked to join as a session keyring the keyring that's already
set as its session, we leak a keyring reference.

This can be tested with the following program:

	#include <stddef.h>
	#include <stdio.h>
	#include <sys/types.h>
	#include <keyutils.h>

	int main(int argc, const char *argv[])
	{
		int i = 0;
		key_serial_t serial;

		serial = keyctl(KEYCTL_JOIN_SESSION_KEYRING,
				"leaked-keyring");
		if (serial < 0) {
			perror("keyctl");
			return -1;
		}

		if (keyctl(KEYCTL_SETPERM, serial,
			   KEY_POS_ALL | KEY_USR_ALL) < 0) {
			perror("keyctl");
			return -1;
		}

		for (i = 0; i < 100; i++) {
			serial = keyctl(KEYCTL_JOIN_SESSION_KEYRING,
					"leaked-keyring");
			if (serial < 0) {
				perror("keyctl");
				return -1;
			}
		}

		return 0;
	}

If, after the program has run, there something like the following line in
/proc/keys:

3f3d898f I--Q---   100 perm 3f3f0000     0     0 keyring   leaked-keyring: empty

with a usage count of 100 * the number of times the program has been run,
then the kernel is malfunctioning.  If leaked-keyring has zero usages or
has been garbage collected, then the problem is fixed.

Reported-by: Yevgeny Pats <yevgeny@perception-point.io>
Signed-off-by: David Howells <dhowells@redhat.com>
Acked-by: Don Zickus <dzickus@redhat.com>
Acked-by: Prarit Bhargava <prarit@redhat.com>
Acked-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: James Morris <james.l.morris@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 security/keys/process_keys.c |    1 +
 1 file changed, 1 insertion(+)

--- a/security/keys/process_keys.c
+++ b/security/keys/process_keys.c
@@ -794,6 +794,7 @@ long join_session_keyring(const char *na
 		ret = PTR_ERR(keyring);
 		goto error2;
 	} else if (keyring == new->session_keyring) {
+		key_put(keyring);
 		ret = 0;
 		goto error2;
 	}

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 4.3 00/55] 4.3.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 41/55] skbuff: Fix offset error in skb_reorder_vlan_header Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 37/55] sh_eth: fix kernel oops in skb_put() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 34/55] openvswitch: Respect conntrack zone even if invalid Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 39/55] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 33/55] openvswitch: Fix helper reference leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 22/55] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 29/55] net: qca_spi: fix transmit queue timeout handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 30/55] r8152: fix lockup when runtime PM is enabled Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 10/55] USB: serial: Another Infineon flash loader USB ID Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 47/55] inet: tcp: fix inetpeer_set_addr_v4() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 19/55] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 05/55] ACPI: Using correct irq when waiting for events Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 11/55] usb-storage: Fix scsi-sd failure "Invalid field in cdb" for USB adapter JMicron Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 55/55] KEYS: Fix keyring ref leak in join_session_keyring() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 01:50 +0100
  [PATCH 4.3 26/55] sctp: update the netstamp_needed counter when copying sockets Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 07/55] tpm, tpm_tis: fix tpm_tis ACPI detection issue with TPM 2.0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 16/55] USB: host: ohci-at91: fix a crash in ohci_hcd_at91_overcurrent_irq Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 09/55] USB: cdc_acm: Ignore Infineon Flash Loader utility Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 14/55] USB: whci-hcd: add check for dma mapping error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 43/55] net_sched: make qdisc_tree_decrease_qlen() work for non mq Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 24/55] vxlan: fix incorrect RCO bit in VXLAN header Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 42/55] net: check both type and procotol for tcp sockets Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 17/55] usb: musb: USB_TI_CPPI41_DMA requires dmaengine support Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 15/55] usb: gadget: pxa27x: fix suspend callback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 45/55] net: fix uninitialized variable issue Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 49/55] gianfar: Dont enable RX Filer if not supported Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 44/55] bluetooth: Validate socket address length in sco_sock_bind(). Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 32/55] phy: micrel: Fix finding PHY properties in MAC node. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 38/55] net: fix IP early demux races Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 21/55] gre6: allow to update all parameters via rtnl Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 35/55] uapi: export ila.h Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 48/55] rhashtable: Enforce minimum size on initial hash table Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 52/55] tcp: restore fastopen with no data in SYN packet Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 06/55] ACPI / PM: Fix incorrect wakeup IRQ setting during suspend-to-idle Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 31/55] ipv6: sctp: clone options to avoid use after free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 18/55] usb: core : hub: Fix BOS NULL pointer kernel panic Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 25/55] sctp: use the same clock as if sock source timestamps were on Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 20/55] pppoe: fix memory corruption in padt work structure Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 27/55] sctp: also copy sk_tsflags when copying the socket Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 03/55] tipc: Fix kfree_skb() of uninitialised pointer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 50/55] fou: clean up socket with kfree_rcu Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:00 +0100
  [PATCH 4.3 01/55] Revert "vrf: fix double free and memory corruption on register_netdevice failure" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-21 02:10 +0100
  Re: [PATCH 4.3 00/55] 4.3.4-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-01-21 02:50 +0100
    Re: [PATCH 4.3 00/55] 4.3.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-22 09:00 +0100
  Re: [PATCH 4.3 00/55] 4.3.4-stable review Mel Gorman <mgorman@techsingularity.net> - 2016-01-21 10:50 +0100
    Re: [PATCH 4.3 00/55] 4.3.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-22 09:00 +0100
      Re: [PATCH 4.3 00/55] 4.3.4-stable review Mel Gorman <mgorman@techsingularity.net> - 2016-01-22 09:20 +0100
  Re: [PATCH 4.3 00/55] 4.3.4-stable review Guenter Roeck <linux@roeck-us.net> - 2016-01-21 13:30 +0100
    Re: [PATCH 4.3 00/55] 4.3.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-22 09:00 +0100

csiph-web