Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1234552

Re: [PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers more robustly

From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers more robustly
Date 2015-09-29 00:40 +0200
Message-ID <qdPfr-4Ba-1@gated-at.bofh.it> (permalink)
References <qcFia-8p1-11@gated-at.bofh.it> <qcFia-8p1-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, Sep 25, 2015 at 10:41 AM, Rasmus Villemoes
<linux@rasmusvillemoes.dk> wrote:
> If we meet any invalid or unsupported format specifier, 'handling' it
> by just printing it as a literal string is not safe: Presumably the
> format string and the arguments passed gcc's type checking, but that
> means something like sprintf(buf, "%n %pd", &intvar, dentry) would end
> up interpreting &intvar as a struct dentry*.
>
> When the offending specifier was %n it used to be at the end of the
> format string, but we can't rely on that always being the case. Also,
> gcc doesn't complain about some more or less exotic qualifiers (or
> 'length modifiers' in posix-speak) such as 'j' or 'q', but being
> unrecognized by the kernel's printf implementation, they'd be
> interpreted as unknown specifiers, and the rest of arguments would be
> interpreted wrongly.
>
> So let's complain about anything we don't understand, not just %n, and
> stop pretending that we'd be able to make sense of the rest of the
> format/arguments. If the offending specifier is in a printk() call we
> unfortunately only get a "BUG: recent printk recursion!", but at least
> direct users of the sprintf family will be caught.

I like it! Thanks :)

Acked-by: Kees Cook <keescook@chromium.org>

-Kees

-- 
Kees Cook
Chrome OS Security
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers more robustly Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2015-09-25 19:50 +0200
  Re: [PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers  more robustly Andy Shevchenko <andriy.shevchenko@linux.intel.com> - 2015-09-28 10:10 +0200
    Re: [PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers more robustly Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2015-09-28 22:20 +0200
  Re: [PATCH 1/4] lib/vsprintf.c: handle invalid format specifiers more robustly Kees Cook <keescook@chromium.org> - 2015-09-29 00:40 +0200

csiph-web