Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1464617
| Path | csiph.com!news.mixmin.net!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | Geert Uytterhoeven <geert@linux-m68k.org> |
| Newsgroups | linux.kernel |
| Subject | Re: usercopy: kernel memory exposure attempt detected |
| Date | Wed, 17 Aug 2016 17:20:02 +0200 |
| Message-ID | <s7aNk-2LP-3@gated-at.bofh.it> (permalink) |
| References | <s77Z8-TF-21@gated-at.bofh.it> <s7atY-2oK-9@gated-at.bofh.it> |
| X-Original-To | Kees Cook <keescook@chromium.org> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=CCvJner+td/TJ7/A7Z8EfyOhvkfKjMlCHZPeKgB1nTI=; b=VUAAEAa66FwJlybo0OW/lXADRvNDJ8ZoGKVltyQ0wTmYeBnc5rpRaFOsy7BxPo/zn8 Y/7Rsh5VrXZc80xbIihXZ7dMn3zi13/nxNv7f573eo7k2QvDr+uFdtdFgXG4vWkwhTgI DhyKXzqe+ttfvv3X2NkKrWbmwsXtt/8U3OXRiN/EeLSm8xlJDko1umho+Ej0lpGMqA0z hcJ2LceCNerSDfzToNhpby4o2gdnqyW3mAqkRvPbMcV00uRxm5UXqCp/75ZmK7FgW9hz V5VFe332zs9LUCP1X1scIlKcPB2q6aTyeU40IzJS21dZWDZbCdYuiRjQUaGPtYuqECeW v9IQ== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=CCvJner+td/TJ7/A7Z8EfyOhvkfKjMlCHZPeKgB1nTI=; b=jwZw8GKq5jp7T814LCAAIkbmZfso62M+fYzafJAfwVeKEUHYr/huJkBuWxhaBjeA/I 35j94OrsLRtddN347XxKZ2+1S4EPYqriWgQBBVwpLIBo0XK3jCqChBvD5GCa0BjWc9nl x4eI38Sex+JMIvNGnYRS3qk6kyycj1nAR4POret0/iAdFr5pY+JwWN52p1+IPO+531bv /HjHz3tRfD38WsmG0rFxKVhWJ0oK87opAcXudT2UqYAw0dZ+/8HOiagvQPphsV6kUoTb 1EtQIamhGJZ/RuRAX4uam60ibuscE8n+BTLHcOgt+POMOF3IsXZgipX2IReyoLeRyg2J 6WPA== |
| X-Gm-Message-State | AEkoouu0yT42c3C7ExOS+AOEd/tBD2vQYG0Y7KSmOsJ0fFszW0VS6r8qhM1PNTC4Ejp4h3P8YNozTB4AE0HbTQ== |
| X-Received | by 10.107.192.69 with SMTP id q66mr48933418iof.5.1471446893627; Wed, 17 Aug 2016 08:14:53 -0700 (PDT) |
| MIME-Version | 1.0 |
| X-Google-Sender-Auth | Z7hnqXFonj2Nb1_AlSkksRRM6zE |
| Content-Type | text/plain; charset=UTF-8 |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 45 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | Al Viro <viro@zeniv.linux.org.uk>, Linux MM <linux-mm@kvack.org>, "open list:NFS, SUNRPC, AND..." <linux-nfs@vger.kernel.org>, "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>, Rik van Riel <riel@redhat.com> |
| X-Original-Date | Wed, 17 Aug 2016 17:14:53 +0200 |
| X-Original-Message-ID | <CAMuHMdURgo0UB6961bZXkb-HV5P3wDT8hgHy=TcPRhA10GT2iw@mail.gmail.com> |
| X-Original-References | <CAMuHMdU+j50GFT=DUWsx_dz1VJJ5zY2EVJi4cX4ZhVVLRMyjCA@mail.gmail.com> <CAGXu5jJ0OCR995Xu41SQvw2YQX-JUO5BhVyOuy0=wJ3Su07puw@mail.gmail.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1464617 |
Show key headers only | View raw
Hi Kees,
On Wed, Aug 17, 2016 at 4:52 PM, Kees Cook <keescook@chromium.org> wrote:
> On Wed, Aug 17, 2016 at 5:13 AM, Geert Uytterhoeven
> <geert@linux-m68k.org> wrote:
>> Saw this when using NFS root on r8a7791/koelsch, using a tree based on
>> renesas-drivers-2016-08-16-v4.8-rc2:
>>
>> usercopy: kernel memory exposure attempt detected from c01ff000
>> (<kernel text>) (4096 bytes)
>
> Hmmm, the kernel text exposure on ARM usually means the hardened
> usercopy patchset was applied to an ARM tree without the _etext patch:
> http://git.kernel.org/linus/14c4a533e0996f95a0a64dfd0b6252d788cebc74
>
> If you _do_ have this patch already (and based on the comment below, I
> suspect you do: usually the missing _etext makes the system entirely
> unbootable), then we need to dig further.
Yes, I do have that patch.
>> Despite the BUG(), the system continues working.
>
> I assume exim4 got killed, though?
Possibly. I don't really use email on the development boards.
Just a debootstrapped Debian NFS root.
> If you can figure out what bytes are present at c01ff000, that may
> give us a clue.
I've added a print_hex_dump(), so we'll find out when it happens again...
Thanks!
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
usercopy: kernel memory exposure attempt detected Geert Uytterhoeven <geert@linux-m68k.org> - 2016-08-17 14:20 +0200
Re: usercopy: kernel memory exposure attempt detected Kees Cook <keescook@chromium.org> - 2016-08-17 17:00 +0200
Re: usercopy: kernel memory exposure attempt detected Geert Uytterhoeven <geert@linux-m68k.org> - 2016-08-17 17:20 +0200
Re: usercopy: kernel memory exposure attempt detected Kees Cook <keescook@chromium.org> - 2016-08-19 23:10 +0200
csiph-web