Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1735411

Re: [PATCH v2 0/3] x86/fpu: prevent leaking FPU registers via invalid FPU state

Path csiph.com!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH v2 0/3] x86/fpu: prevent leaking FPU registers via invalid FPU state
Date Wed, 20 Sep 2017 05:10:02 +0200
Message-ID <urDyG-5Fl-9@gated-at.bofh.it> (permalink)
References <urBnb-42V-5@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=N5s39NoPzcntB0gMpjJC22GOXNEJ/6EYJCDMNaDqBOo=; b=kc/tKKAwwsdtmh3JtTQb96/Dp5PmVOPrkxSebf0xqI5Mt9Rs2SgFL4Kzl0vkm9qkUE 1Ss8s7ykLoRS3NdxEsEMdrrLPTLKmLdcveD7sWv4Mzg/vq47pfPGfn/D8gwVRLlH2/V7 2qpiiAe6qcuVLmFHfCjzCKxkjMNjwguzjtpiCaqTt1advBFHQrbbbG33nxILkWrgcCyw TO4S2a8xa9gn5Ck8hMQkXnxXC1AF6LP1s6VMFXkzeEsJR0K9409lDHM1GNFNO+/XdQnG XIXQPVYGl951g1M+mRyMjmBYYLAb0YFLrrfHk4fLDmqDquCvTZ8Fyv6yauDc3NlypJSZ t6ZA==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=N5s39NoPzcntB0gMpjJC22GOXNEJ/6EYJCDMNaDqBOo=; b=Ceq/1W3/innaGb1DVPhNeJKaBtOj4+ogVptgo2q+81mN8kF5tQjJzhzZyIedo5acpa 1RQBan8SFeSFvBMM7oUszq7faqqY696EOEyvQSZdmurXn50iWzdwR67T+zYg2ecGIJgO UQJE4d6dj1S50qkGh+XMuTXAyf+EmNxwS/8mY=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=N5s39NoPzcntB0gMpjJC22GOXNEJ/6EYJCDMNaDqBOo=; b=Om1qWu+nsuovkFtC3KTKXpCkzUjpzWBZ7+OLo0ABjTETAuPzsER9S5tzj725ClYy8y 2cqTtuCLcpAp2pivMpMNLeu1WcUeSWK1MGkB7dw1rTJwTMf5WOwlVjSstkKf0vKpGuUw aqyDDj+MJsVDalm40WGM/4WuCZu32IGOMwPDuBm1FTTsBOoTZakVaJd1GGgoYs924o12 YDmqdqPLKZSrt45gXYuFW/QRIxbtsqF9uoKwIn8ZAy/n4LL3Z4E1+z9DzRFYJz1ntpIv h5Bphf8IRxgN8SnsY81Z3aRup8+NHTEcdX6Leyt5Qp7+s9RIvE41TM+kOytYRdeeyHtd vrmg==
X-Gm-Message-State AHPjjUiINF+3JqZNut2bAZQFI/2KqCTYtvkNnhJyxbtWl5zvOBDYe3Zu ZhXN3/gGXLRJE/wxBz+P2MtiEqAAZzAiuu8tSfXV8g==
X-Google-SMTP-Source AOwi7QDLcEEq6sRNyqUOpQcqoPEXU5Ra+sdxi1uqU3rIHiQXyZfcQF11ESW67Gt8sKwAdXIW2oWmy5MTQdnmbnwTdd4=
X-Received by 10.36.141.67 with SMTP id w64mr984822itd.8.1505876585918; Tue, 19 Sep 2017 20:03:05 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth 6wKC9B11reZ_-Is8m2Vfg3vZMhs
Content-Type text/plain; charset="UTF-8"
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 41
Organization linux.* mail to news gateway
X-Original-Cc "x86@kernel.org" <x86@kernel.org>, LKML <linux-kernel@vger.kernel.org>, "kernel-hardening@lists.openwall.com" <kernel-hardening@lists.openwall.com>, Andy Lutomirski <luto@kernel.org>, Dave Hansen <dave.hansen@linux.intel.com>, Dmitry Vyukov <dvyukov@google.com>, Fenghua Yu <fenghua.yu@intel.com>, Kevin Hao <haokexin@gmail.com>, Oleg Nesterov <oleg@redhat.com>, Wanpeng Li <wanpeng.li@hotmail.com>, Yu-cheng Yu <yu-cheng.yu@intel.com>, Michael Halcrow <mhalcrow@google.com>, Eric Biggers <ebiggers@google.com>
X-Original-Date Tue, 19 Sep 2017 20:03:05 -0700
X-Original-Message-ID <CAGXu5jJsA-y1yDre5cQ9j8S4i0ftt=Rk5GaXP8wunmm09rrUNg@mail.gmail.com>
X-Original-References <20170920004434.35308-1-ebiggers3@gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1735411

Show key headers only | View raw


On Tue, Sep 19, 2017 at 5:44 PM, Eric Biggers <ebiggers3@gmail.com> wrote:
> From: Eric Biggers <ebiggers@google.com>
>
> This is a second attempt to fix the bug found by syzkaller where the
> ptrace syscall can be used to set invalid bits in a task's FPU state.
> I also found that an equivalent bug was reachable using the sigreturn
> syscall, so the first patch fixes the bug in both cases.
>
> The other two patches start validating the other parts of the
> xstate_header and make it so that invalid FPU states can no longer be
> abused to leak the FPU registers of other processes.
>
> Eric Biggers (3):
>   x86/fpu: don't let userspace set bogus xcomp_bv
>   x86/fpu: tighten validation of user-supplied xstate_header
>   x86/fpu: reinitialize FPU registers if restoring FPU state fails

This series looks sensible to me! Thanks for getting this fixed up.

Reviewed-by: Kees Cook <keescook@chromium.org>

-Kees

>
>  arch/x86/include/asm/fpu/internal.h | 29 ++++++++++++++++++++---------
>  arch/x86/include/asm/fpu/xstate.h   | 19 +++++++++++++++++++
>  arch/x86/kernel/fpu/core.c          | 16 ++++++++++++++++
>  arch/x86/kernel/fpu/regset.c        | 20 +++++++++-----------
>  arch/x86/kernel/fpu/signal.c        | 15 +++++++++++----
>  arch/x86/kernel/fpu/xstate.c        | 27 ++++++++++-----------------
>  6 files changed, 85 insertions(+), 41 deletions(-)
>
> --
> 2.14.1.690.gbb1197296e-goog
>



-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

[PATCH v2 0/3] x86/fpu: prevent leaking FPU registers via invalid FPU state Eric Biggers <ebiggers3@gmail.com> - 2017-09-20 02:50 +0200
  [PATCH v2 1/3] x86/fpu: don't let userspace set bogus xcomp_bv Eric Biggers <ebiggers3@gmail.com> - 2017-09-20 02:50 +0200
    Re: [lkp-robot] [x86/fpu]  14e633085a:  Kernel_panic-not_syncing:Attempted_to_kill_init!exitcode= Eric Biggers <ebiggers3@gmail.com> - 2017-09-26 05:10 +0200
  Re: [PATCH v2 0/3] x86/fpu: prevent leaking FPU registers via invalid  FPU state Kees Cook <keescook@chromium.org> - 2017-09-20 05:10 +0200

csiph-web