Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1353860

[PATCH] mm/mempool: Avoid KASAN marking mempool posion checks as use-after-free

From Matthew Dawson <matthew@mjdsystems.ca>
Newsgroups linux.kernel
Subject [PATCH] mm/mempool: Avoid KASAN marking mempool posion checks as use-after-free
Date 2016-03-09 07:30 +0100
Message-ID <raFN8-41M-15@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


When removing an element from the mempool, mark it as unpoisoned in KASAN
before verifying its contents for SLUB/SLAB debugging.  Otherwise KASAN
will flag the reads checking the element use-after-free writes as
use-after-free reads.

Signed-off-by: Matthew Dawson <matthew@mjdsystems.ca>
---
 mm/mempool.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/mm/mempool.c b/mm/mempool.c
index 004d42b..7924f4f 100644
--- a/mm/mempool.c
+++ b/mm/mempool.c
@@ -135,8 +135,8 @@ static void *remove_element(mempool_t *pool)
 	void *element = pool->elements[--pool->curr_nr];
 
 	BUG_ON(pool->curr_nr < 0);
-	check_element(pool, element);
 	kasan_unpoison_element(pool, element);
+	check_element(pool, element);
 	return element;
 }
 
-- 
2.7.1

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH] mm/mempool: Avoid KASAN marking mempool posion checks as use-after-free Matthew Dawson <matthew@mjdsystems.ca> - 2016-03-09 07:30 +0100
  Re: [PATCH] mm/mempool: Avoid KASAN marking mempool posion checks as  use-after-free Andrey Ryabinin <aryabinin@virtuozzo.com> - 2016-03-10 15:00 +0100

csiph-web