Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1644191

[PATCH 4.4 34/56] fs/xattr.c: zero out memory copied to userspace in getxattr

From Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject [PATCH 4.4 34/56] fs/xattr.c: zero out memory copied to userspace in getxattr
Date 2017-05-18 13:10 +0200
Message-ID <tIrtG-1zL-61@gated-at.bofh.it> (permalink)
References <tIrtD-1zL-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michal Hocko <mhocko@suse.com>

commit 81be3dee96346fbe08c31be5ef74f03f6b63cf68 upstream.

getxattr uses vmalloc to allocate memory if kzalloc fails.  This is
filled by vfs_getxattr and then copied to the userspace.  vmalloc,
however, doesn't zero out the memory so if the specific implementation
of the xattr handler is sloppy we can theoretically expose a kernel
memory.  There is no real sign this is really the case but let's make
sure this will not happen and use vzalloc instead.

Fixes: 779302e67835 ("fs/xattr.c:getxattr(): improve handling of allocation failures")
Link: http://lkml.kernel.org/r/20170306103327.2766-1-mhocko@kernel.org
Acked-by: Kees Cook <keescook@chromium.org>
Reported-by: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Michal Hocko <mhocko@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/xattr.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/xattr.c
+++ b/fs/xattr.c
@@ -442,7 +442,7 @@ getxattr(struct dentry *d, const char __
 			size = XATTR_SIZE_MAX;
 		kvalue = kzalloc(size, GFP_KERNEL | __GFP_NOWARN);
 		if (!kvalue) {
-			vvalue = vmalloc(size);
+			vvalue = vzalloc(size);
 			if (!vvalue)
 				return -ENOMEM;
 			kvalue = vvalue;

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 4.4 00/56] 4.4.69-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 54/56] wlcore: Pass win_size taken from ieee80211_sta to FW Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 34/56] fs/xattr.c: zero out memory copied to userspace in getxattr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 52/56] mac80211: pass block ack session timeout to to driver Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 42/56] padata: free correct variable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 56/56] ipmi: Fix kernel panic at ipmi_ssif_thread() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 17/56] usb: hub: Do not attempt to autosuspend disconnected devices Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 24/56] KVM: arm/arm64: fix races in kvm_psci_vcpu_on Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 09/56] staging: vt6656: use off stack for in buffer USB transfers. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 33/56] ext4: evict inline data when writing to memory map Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 51/56] mac80211: pass RX aggregation window size to driver Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 38/56] SMB3: Work around mount failure when using SMB3 dialect to Macs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 55/56] wlcore: Add RX_BA_WIN_SIZE_CHANGE_EVENT event Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 45/56] serial: omap: fix runtime-pm handling on unbind Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 03/56] target/fileio: Fix zero-length READ and WRITE handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 50/56] Bluetooth: hci_intel: add missing tty-device sanity check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 46/56] serial: omap: suspend device on probe errors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 28/56] vfio/type1: Remove locked page accounting workqueue Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 44/56] serial: samsung: Use right device for DMA-mapping calls Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 36/56] fs/block_dev: always invalidate cleancache in invalidate_bdev() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 08/56] USB: Proper handling of Race Condition when two USB class drivers try to call init_usb_class simultaneously Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 05/56] iscsi-target: Set session_fall_back_to_erl0 when forcing reinstatement Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 12/56] staging: comedi: jr3_pci: fix possible null pointer dereference Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:10 +0200
  [PATCH 4.4 20/56] selftests/x86/ldt_gdt_32: Work around a glibc sigaction() bug Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 04/56] target: Convert ACL change queue_depth se_session reference usage Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 27/56] dm era: save spacemap metadata root after the pre-commit Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 22/56] um: Fix PTRACE_POKEUSER on x86_64 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 10/56] staging: vt6656: use off stack for out buffer USB transfers. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 18/56] usb: misc: legousbtower: Fix buffers on stack Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 14/56] usb: misc: add missing continue in switch Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 21/56] x86, pmem: Fix cache flushing for iovec write < 8 bytes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 16/56] usb: hub: Fix error loop seen after hub communication errors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 15/56] usb: Make sure usb/phy/of gets built-in Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 11/56] staging: gdm724x: gdm_mux: fix use-after-free on module unload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 29/56] IB/core: Fix sysfs registration error flow Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 19/56] x86/boot: Fix BSS corruption/overwrite bug in early x86 kernel startup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  [PATCH 4.4 25/56] block: fix blk_integrity_register to use templates interval_exp if not 0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-18 13:20 +0200
  Re: [PATCH 4.4 00/56] 4.4.69-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-18 19:40 +0200
  Re: [PATCH 4.4 00/56] 4.4.69-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-19 03:20 +0200

csiph-web