Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1590687

Re: fs: use-after-free in userfaultfd_exit

From Andrea Arcangeli <aarcange@redhat.com>
Newsgroups linux.kernel
Subject Re: fs: use-after-free in userfaultfd_exit
Date 2017-03-02 00:20 +0100
Message-ID <tglHk-1Og-17@gated-at.bofh.it> (permalink)
References <tghu2-73E-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed, Mar 01, 2017 at 07:48:00PM +0100, Dmitry Vyukov wrote:
> Hello,
> 
> I've got the following use-after-free report while running syzkaller
> fuzzer on 86292b33d4b79ee03e2f43ea0381ef85f077c760:

Yes, I posted the fix for this one last Friday, I found it during
stress testing, it triggered the first time post-upstream merging
despite I was running the same stress testing with SLUB poisoning
enabled before.

This affects all apps, also the ones that don't use userfaultfd, it's
a locking issue. Furthermore the cost of userfaultfd_exit was not
acceptable, if something it had to be activated by a flag in mm->flags
(such an optimization would have been absolutely trivial though).

Thankfully I realized another feature (UFFDIO_COPY -ENOSPC retval) can
provide the same information at zero cost so I could drop
userfaultfd_exit as a whole.

https://marc.info/?l=linux-mm&m=148796041217814&w=2

The fix is already included in -mm along with the other fix for
VM_FAULT_NOPAGE.

Thanks,
Andrea

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

fs: use-after-free in userfaultfd_exit Dmitry Vyukov <dvyukov@google.com> - 2017-03-01 19:50 +0100
  Re: fs: use-after-free in userfaultfd_exit Andrea Arcangeli <aarcange@redhat.com> - 2017-03-02 00:20 +0100

csiph-web