Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1380863
| Path | csiph.com!news.mixmin.net!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | Sasha Levin <sasha.levin@oracle.com> |
| Newsgroups | linux.kernel |
| Subject | Re: bpf: use-after-free in array_map_alloc |
| Date | Mon, 18 Apr 2016 00:50:01 +0200 |
| Message-ID | <rp3FT-3dd-5@gated-at.bofh.it> (permalink) |
| References | <roYdd-7sb-27@gated-at.bofh.it> <roYPT-83E-1@gated-at.bofh.it> |
| X-Original-To | Alexei Starovoitov <alexei.starovoitov@gmail.com> |
| User-Agent | Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.6.0 |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=windows-1252 |
| Content-Transfer-Encoding | 7bit |
| X-Source-IP | userv0021.oracle.com [156.151.31.71] |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 22 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | ast@kernel.org, "netdev@vger.kernel.org" <netdev@vger.kernel.org>, LKML <linux-kernel@vger.kernel.org>, Tejun Heo <tj@kernel.org> |
| X-Original-Date | Sun, 17 Apr 2016 18:45:44 -0400 |
| X-Original-Message-ID | <57141218.4000103@oracle.com> |
| X-Original-References | <5713C0AD.3020102@oracle.com> <20160417172943.GA83672@ast-mbp.thefacebook.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1380863 |
Show key headers only | View raw
On 04/17/2016 01:29 PM, Alexei Starovoitov wrote: > On Sun, Apr 17, 2016 at 12:58:21PM -0400, Sasha Levin wrote: >> > Hi all, >> > >> > I've hit the following while fuzzing with syzkaller inside a KVM tools guest >> > running the latest -next kernel: > thanks for the report. Adding Tejun... > if I read the report correctly it's not about bpf, but rather points to > the issue inside percpu logic. > First __alloc_percpu_gfp() is called, then the memory is freed with > free_percpu() which triggers async pcpu_balance_work and then > pcpu_extend_area_map is hitting use-after-free. > I guess bpf percpu array map is stressing this logic the most. > Any simpler steps to reproduce ? No simple way to reproduce. I blamed bpf because I saw a few traces and it was only bpf that was causing it, there was no other reasoning behind it. Thanks, Sasha
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
bpf: use-after-free in array_map_alloc Sasha Levin <sasha.levin@oracle.com> - 2016-04-17 19:00 +0200
Re: bpf: use-after-free in array_map_alloc Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2016-04-17 19:40 +0200
Re: bpf: use-after-free in array_map_alloc Sasha Levin <sasha.levin@oracle.com> - 2016-04-18 00:50 +0200
csiph-web