Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1464815
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! |
| Date | 2016-08-17 23:40 +0200 |
| Message-ID | <s7gJ3-6VE-5@gated-at.bofh.it> (permalink) |
| References | <s77Z7-TF-9@gated-at.bofh.it> <s7bJo-3pe-19@gated-at.bofh.it> <s7gzn-6R5-1@gated-at.bofh.it> <s7gJ3-6VE-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Aug 17, 2016 at 2:30 PM, Linus Torvalds <torvalds@linux-foundation.org> wrote: > On Wed, Aug 17, 2016 at 2:25 PM, Kees Cook <keescook@chromium.org> wrote: >> >> I had forwarded this bug Rik's way since the page-cross checking was >> suggested by him. I'm happy to drop it; it was a suggested improvement >> that was suspected to be safe (none of the folks testing this ran into >> it and we saw no report during its time in -next). I can prepare a >> patch if there isn't a better way to detect this kind of allocation. >> (FWIW, slab is handled separately.) > > I can't think of any sane way to notice it normally. > > Yes, with __GFP_COMPOUND you get the compound flag bits set, but as > mentioned, that's a special case for the large page VM handling, and > not applicable in general. > > Very few things do higher order allocations outside of slab and the > task struct. But it does happen. Even fewer of those then have > contents that might get copied to user space, but it clearly happens > at least for _one_ case, and I can't convince myself that there might > not be other cases too.. Yup, totally, I'll send a patch to remove this and Rik and I can investigate re-adding it later. -Kees -- Kees Cook Nexus Security
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-17 18:20 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-17 23:30 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-17 23:40 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-17 23:40 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Rik van Riel <riel@redhat.com> - 2016-08-17 23:50 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
csiph-web