Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1656340

[PATCH 5/6] arm64: move COMPAT_ELF_ET_DYN_BASE lower in the address space

From riel@redhat.com
Newsgroups linux.kernel
Subject [PATCH 5/6] arm64: move COMPAT_ELF_ET_DYN_BASE lower in the address space
Date 2017-06-02 17:30 +0200
Message-ID <tNWGv-2XT-27@gated-at.bofh.it> (permalink)
References <tNWGu-2XT-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Rik van Riel <riel@redhat.com>

When setting up mmap_base, we take care to start the mmap base
below the maximum extent to which the stack will grow. However,
we take no such precautions with PIE binaries, which are placed
at 2/3 of TASK_SIZE plus a random offset. As a result, 32 bit PIE
binaries can end up smack in the middle of where the stack (which
is randomized down) is supposed to go.

That problem can be avoided by putting the 32 bit ELF_ET_DYN_BASE
at 256MB, which is a value linux-hardened and grsecurity have used
for a long time now without any known (to me) bug reports.

Signed-off-by: Rik van Riel <riel@redhat.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
---
 arch/arm64/include/asm/elf.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/include/asm/elf.h b/arch/arm64/include/asm/elf.h
index 5d1700425efe..88808a761816 100644
--- a/arch/arm64/include/asm/elf.h
+++ b/arch/arm64/include/asm/elf.h
@@ -173,7 +173,7 @@ extern int arch_setup_additional_pages(struct linux_binprm *bprm,
 
 #ifdef CONFIG_COMPAT
 
-#define COMPAT_ELF_ET_DYN_BASE		(2 * TASK_SIZE_32 / 3)
+#define COMPAT_ELF_ET_DYN_BASE		(0x10000000UL)
 
 /* AArch32 registers. */
 #define COMPAT_ELF_NGREG		18
-- 
2.9.3

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/6] move mmap_area and PIE binaries away from the stack riel@redhat.com - 2017-06-02 17:30 +0200
  [PATCH 1/6] binfmt_elf: document load_bias a little bit riel@redhat.com - 2017-06-02 17:30 +0200
    Re: [kernel-hardening] [PATCH 1/6] binfmt_elf: document load_bias a  little bit Kees Cook <keescook@chromium.org> - 2017-06-02 21:30 +0200
  [PATCH 6/6] powerpc,mmap: properly account for stack randomization in mmap_base riel@redhat.com - 2017-06-02 17:30 +0200
  [PATCH 4/6] arm64/mmap: properly account for stack randomization in mmap_base riel@redhat.com - 2017-06-02 17:30 +0200
  [PATCH 2/6] x86/elf: move 32 bit ELF_ET_DYN_BASE to 256MB riel@redhat.com - 2017-06-02 17:30 +0200
    Re: [PATCH 2/6] x86/elf: move 32 bit ELF_ET_DYN_BASE to 256MB Kees Cook <keescook@chromium.org> - 2017-06-03 06:30 +0200
      Re: [PATCH 2/6] x86/elf: move 32 bit ELF_ET_DYN_BASE to 256MB Daniel Micay <danielmicay@gmail.com> - 2017-06-03 14:00 +0200
      Re: [PATCH 2/6] x86/elf: move 32 bit ELF_ET_DYN_BASE to 256MB Rik van Riel <riel@redhat.com> - 2017-06-05 16:00 +0200
  [PATCH 3/6] x86/mmap: properly account for stack randomization in mmap_base riel@redhat.com - 2017-06-02 17:30 +0200
    Re: [kernel-hardening] [PATCH 3/6] x86/mmap: properly account for  stack randomization in mmap_base Kees Cook <keescook@chromium.org> - 2017-06-03 06:50 +0200
      Re: [kernel-hardening] [PATCH 3/6] x86/mmap: properly account for  stack randomization in mmap_base Daniel Micay <danielmicay@gmail.com> - 2017-06-03 14:20 +0200
  [PATCH 5/6] arm64: move COMPAT_ELF_ET_DYN_BASE lower in the address space riel@redhat.com - 2017-06-02 17:30 +0200
  Re: [kernel-hardening] [PATCH 0/6] move mmap_area and PIE binaries  away from the stack Kees Cook <keescook@chromium.org> - 2017-06-03 06:40 +0200
    Re: [kernel-hardening] [PATCH 0/6] move mmap_area and PIE binaries  away from the stack Daniel Micay <danielmicay@gmail.com> - 2017-06-03 14:20 +0200

csiph-web