Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1397551
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.19.y-ckt 14/54] mm: split ET_DYN ASLR from mmap ASLR |
| Date | 2016-05-10 02:10 +0200 |
| Message-ID | <rx3pp-81T-35@gated-at.bofh.it> (permalink) |
| References | <rx3pn-81T-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
3.19.8-ckt21 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Kees Cook <keescook@chromium.org>
commit d1fd836dcf00d2028c700c7e44d2c23404062c90 upstream.
This fixes the "offset2lib" weakness in ASLR for arm, arm64, mips,
powerpc, and x86. The problem is that if there is a leak of ASLR from
the executable (ET_DYN), it means a leak of shared library offset as
well (mmap), and vice versa. Further details and a PoC of this attack
is available here:
http://cybersecurity.upv.es/attacks/offset2lib/offset2lib.html
With this patch, a PIE linked executable (ET_DYN) has its own ASLR
region:
$ ./show_mmaps_pie
54859ccd6000-54859ccd7000 r-xp ... /tmp/show_mmaps_pie
54859ced6000-54859ced7000 r--p ... /tmp/show_mmaps_pie
54859ced7000-54859ced8000 rw-p ... /tmp/show_mmaps_pie
7f75be764000-7f75be91f000 r-xp ... /lib/x86_64-linux-gnu/libc.so.6
7f75be91f000-7f75beb1f000 ---p ... /lib/x86_64-linux-gnu/libc.so.6
7f75beb1f000-7f75beb23000 r--p ... /lib/x86_64-linux-gnu/libc.so.6
7f75beb23000-7f75beb25000 rw-p ... /lib/x86_64-linux-gnu/libc.so.6
7f75beb25000-7f75beb2a000 rw-p ...
7f75beb2a000-7f75beb4d000 r-xp ... /lib64/ld-linux-x86-64.so.2
7f75bed45000-7f75bed46000 rw-p ...
7f75bed46000-7f75bed47000 r-xp ...
7f75bed47000-7f75bed4c000 rw-p ...
7f75bed4c000-7f75bed4d000 r--p ... /lib64/ld-linux-x86-64.so.2
7f75bed4d000-7f75bed4e000 rw-p ... /lib64/ld-linux-x86-64.so.2
7f75bed4e000-7f75bed4f000 rw-p ...
7fffb3741000-7fffb3762000 rw-p ... [stack]
7fffb377b000-7fffb377d000 r--p ... [vvar]
7fffb377d000-7fffb377f000 r-xp ... [vdso]
The change is to add a call the newly created arch_mmap_rnd() into the
ELF loader for handling ET_DYN ASLR in a separate region from mmap ASLR,
as was already done on s390. Removes CONFIG_BINFMT_ELF_RANDOMIZE_PIE,
which is no longer needed.
Signed-off-by: Kees Cook <keescook@chromium.org>
Reported-by: Hector Marco-Gisbert <hecmargi@upv.es>
Cc: Russell King <linux@arm.linux.org.uk>
Reviewed-by: Ingo Molnar <mingo@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Will Deacon <will.deacon@arm.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Paul Mackerras <paulus@samba.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Martin Schwidefsky <schwidefsky@de.ibm.com>
Cc: Heiko Carstens <heiko.carstens@de.ibm.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: "David A. Long" <dave.long@linaro.org>
Cc: Andrey Ryabinin <a.ryabinin@samsung.com>
Cc: Arun Chandran <achandran@mvista.com>
Cc: Yann Droneaud <ydroneaud@opteya.com>
Cc: Min-Hua Chen <orca.chen@gmail.com>
Cc: Paul Burton <paul.burton@imgtec.com>
Cc: Alex Smith <alex@alex-smith.me.uk>
Cc: Markos Chandras <markos.chandras@imgtec.com>
Cc: Vineeth Vijayan <vvijayan@mvista.com>
Cc: Jeff Bailey <jeffbailey@google.com>
Cc: Michael Holzheu <holzheu@linux.vnet.ibm.com>
Cc: Ben Hutchings <ben@decadent.org.uk>
Cc: Behan Webster <behanw@converseincode.com>
Cc: Ismael Ripoll <iripoll@upv.es>
Cc: Jan-Simon Mller <dl9pf@gmx.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/Kconfig | 1 -
arch/arm64/Kconfig | 1 -
arch/mips/Kconfig | 1 -
arch/powerpc/Kconfig | 1 -
arch/s390/include/asm/elf.h | 5 ++---
arch/s390/mm/mmap.c | 8 --------
arch/x86/Kconfig | 1 -
fs/Kconfig.binfmt | 3 ---
fs/binfmt_elf.c | 18 ++++--------------
9 files changed, 6 insertions(+), 33 deletions(-)
diff --git a/arch/arm/Kconfig b/arch/arm/Kconfig
index 8239faa..aec3ea4 100644
--- a/arch/arm/Kconfig
+++ b/arch/arm/Kconfig
@@ -1,7 +1,6 @@
config ARM
bool
default y
- select ARCH_BINFMT_ELF_RANDOMIZE_PIE
select ARCH_HAS_ATOMIC64_DEC_IF_POSITIVE
select ARCH_HAS_ELF_RANDOMIZE
select ARCH_HAS_TICK_BROADCAST if GENERIC_CLOCKEVENTS_BROADCAST
diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig
index 15de145..962b43b 100644
--- a/arch/arm64/Kconfig
+++ b/arch/arm64/Kconfig
@@ -1,6 +1,5 @@
config ARM64
def_bool y
- select ARCH_BINFMT_ELF_RANDOMIZE_PIE
select ARCH_HAS_ATOMIC64_DEC_IF_POSITIVE
select ARCH_HAS_ELF_RANDOMIZE
select ARCH_HAS_GCOV_PROFILE_ALL
diff --git a/arch/mips/Kconfig b/arch/mips/Kconfig
index f50c77f..72fa7c6 100644
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -23,7 +23,6 @@ config MIPS
select HAVE_KRETPROBES
select HAVE_DEBUG_KMEMLEAK
select HAVE_SYSCALL_TRACEPOINTS
- select ARCH_BINFMT_ELF_RANDOMIZE_PIE
select ARCH_HAS_ELF_RANDOMIZE
select HAVE_ARCH_TRANSPARENT_HUGEPAGE if CPU_SUPPORTS_HUGEPAGES && 64BIT
select RTC_LIB if !MACH_LOONGSON
diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig
index e3cd949..3827296 100644
--- a/arch/powerpc/Kconfig
+++ b/arch/powerpc/Kconfig
@@ -88,7 +88,6 @@ config PPC
select ARCH_MIGHT_HAVE_PC_PARPORT
select ARCH_MIGHT_HAVE_PC_SERIO
select BINFMT_ELF
- select ARCH_BINFMT_ELF_RANDOMIZE_PIE
select ARCH_HAS_ELF_RANDOMIZE
select OF
select OF_EARLY_FLATTREE
diff --git a/arch/s390/include/asm/elf.h b/arch/s390/include/asm/elf.h
index 2e63de8..d0db9d9 100644
--- a/arch/s390/include/asm/elf.h
+++ b/arch/s390/include/asm/elf.h
@@ -163,10 +163,9 @@ extern unsigned int vdso_enabled;
the loader. We need to make sure that it is out of the way of the program
that it will "exec", and that there is sufficient room for the brk. 64-bit
tasks are aligned to 4GB. */
-extern unsigned long randomize_et_dyn(void);
-#define ELF_ET_DYN_BASE (randomize_et_dyn() + (is_32bit_task() ? \
+#define ELF_ET_DYN_BASE (is_32bit_task() ? \
(STACK_TOP / 3 * 2) : \
- (STACK_TOP / 3 * 2) & ~((1UL << 32) - 1)))
+ (STACK_TOP / 3 * 2) & ~((1UL << 32) - 1))
/* This yields a mask that user programs can use to figure out what
instruction set this CPU supports. */
diff --git a/arch/s390/mm/mmap.c b/arch/s390/mm/mmap.c
index 8c11536..bb3367c 100644
--- a/arch/s390/mm/mmap.c
+++ b/arch/s390/mm/mmap.c
@@ -177,14 +177,6 @@ arch_get_unmapped_area_topdown(struct file *filp, const unsigned long addr0,
return addr;
}
-unsigned long randomize_et_dyn(void)
-{
- if (current->flags & PF_RANDOMIZE)
- return arch_mmap_rnd();
-
- return 0UL;
-}
-
#ifndef CONFIG_64BIT
/*
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
index ea88e5d..9f6b332 100644
--- a/arch/x86/Kconfig
+++ b/arch/x86/Kconfig
@@ -85,7 +85,6 @@ config X86
select HAVE_CMPXCHG_DOUBLE
select HAVE_ARCH_KMEMCHECK
select HAVE_USER_RETURN_NOTIFIER
- select ARCH_BINFMT_ELF_RANDOMIZE_PIE
select ARCH_HAS_ELF_RANDOMIZE
select HAVE_ARCH_JUMP_LABEL
select ARCH_HAS_ATOMIC64_DEC_IF_POSITIVE
diff --git a/fs/Kconfig.binfmt b/fs/Kconfig.binfmt
index c055d56..58d892d 100644
--- a/fs/Kconfig.binfmt
+++ b/fs/Kconfig.binfmt
@@ -27,9 +27,6 @@ config COMPAT_BINFMT_ELF
bool
depends on COMPAT && BINFMT_ELF
-config ARCH_BINFMT_ELF_RANDOMIZE_PIE
- bool
-
config ARCH_BINFMT_ELF_STATE
bool
diff --git a/fs/binfmt_elf.c b/fs/binfmt_elf.c
index cd0dea9..41bf972 100644
--- a/fs/binfmt_elf.c
+++ b/fs/binfmt_elf.c
@@ -31,6 +31,7 @@
#include <linux/security.h>
#include <linux/random.h>
#include <linux/elf.h>
+#include <linux/elf-randomize.h>
#include <linux/utsname.h>
#include <linux/coredump.h>
#include <linux/sched.h>
@@ -910,21 +911,10 @@ static int load_elf_binary(struct linux_binprm *bprm)
* default mmap base, as well as whatever program they
* might try to exec. This is because the brk will
* follow the loader, and is not movable. */
-#ifdef CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE
- /* Memory randomization might have been switched off
- * in runtime via sysctl or explicit setting of
- * personality flags.
- * If that is the case, retain the original non-zero
- * load_bias value in order to establish proper
- * non-randomized mappings.
- */
+ load_bias = ELF_ET_DYN_BASE - vaddr;
if (current->flags & PF_RANDOMIZE)
- load_bias = 0;
- else
- load_bias = ELF_PAGESTART(ELF_ET_DYN_BASE - vaddr);
-#else
- load_bias = ELF_PAGESTART(ELF_ET_DYN_BASE - vaddr);
-#endif
+ load_bias += arch_mmap_rnd();
+ load_bias = ELF_PAGESTART(load_bias);
total_size = total_mapping_size(elf_phdata,
loc->elf_ex.e_phnum);
if (!total_size) {
--
2.7.4
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[3.19.y-ckt stable] Linux 3.19.8-ckt21 stable review Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 42/54] x86/sysfb_efi: Fix valid BAR address range check Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 53/54] cxgbi: fix uninitialized flowi6 Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 14/54] mm: split ET_DYN ASLR from mmap ASLR Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 51/54] batman-adv: Reduce refcnt of removed router when updating route Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 18/54] ASoC: dapm: Make sure we have a card when displaying component widgets Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 11/54] s390: standardize mmap_rnd() usage Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 04/54] arm: factor out mmap ASLR into mmap_rnd Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 52/54] batman-adv: Fix broadcast/ogm queue limit on a removed interface Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 31/54] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 48/54] jme: Do not enable NIC WoL functions on S0 Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 54/54] net/mlx4_en: fix spurious timestamping callbacks Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 12/54] mm: expose arch_mmap_rnd when available Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:10 +0200
[PATCH 3.19.y-ckt 20/54] i2c: cpm: Fix build break due to incompatible pointer types Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 21/54] i2c: exynos5: Fix possible ABBA deadlock by keeping I2C clock prepared Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 37/54] Minimal fix-up of bad hashing behavior of hash_64() Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 36/54] powerpc: Fix bad inline asm constraint in create_zero_mask() Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 32/54] IB/security: Restrict use of the write() interface Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 24/54] USB: serial: cp210x: add Straizona Focusers device ids Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 09/54] s390: avoid z13 cache aliasing Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 34/54] mm: vmscan: reclaim highmem zone if buffer_heads is over limit Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 28/54] cxl: Keep IRQ mappings on context teardown Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 26/54] workqueue: fix ghost PENDING flag while doing MQ IO Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 27/54] drm/dp/mst: Get validated port ref in drm_dp_update_payload_part1() Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 29/54] drm/i915: Fix system resume if PCI device remained enabled Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 08/54] powerpc: standardize mmap_rnd() usage Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 40/54] MAINTAINERS: Remove asterisk from EFI directory names Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 41/54] ACPICA: Dispatcher: Update thread ID for recursive method calls Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 47/54] parisc: fix a bug when syscall number of tracee is __NR_Linux_syscalls Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 25/54] ALSA: hda - Add dock support for ThinkPad X260 Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 23/54] USB: serial: cp210x: add ID for Link ECU Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 13/54] s390: redefine randomize_et_dyn for ELF_ET_DYN_BASE Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 30/54] drm/i915/ddi: Fix eDP VDD handling during booting and suspend/resume Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 35/54] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 06/54] arm64: standardize mmap_rnd() usage Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 43/54] fs/pnode.c: treat zero mnt_group_id-s as unequal Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 44/54] propogate_mnt: Handle the first propogated copy being a slave Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 33/54] mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 10/54] s390/mm: align 64-bit PIE binaries to 4GB Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 17/54] ASoC: rt5640: Correct the digital interface data select Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 46/54] x86/tsc: Read all ratio bits from MSR_PLATFORM_INFO Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 39/54] drm/radeon: make sure vertical front porch is at least 1 Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 19/54] iio: ak8975: Fix NULL pointer exception on early interrupt Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:20 +0200
[PATCH 3.19.y-ckt 07/54] mips: extract logic for mmap_rnd() Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:30 +0200
[PATCH 3.19.y-ckt 01/54] [3.19-stable-only] Revert "powerpc: Update TM user feature bits in scan_features()" Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:30 +0200
Re: [PATCH 3.19.y-ckt 01/54] [3.19-stable-only] Revert "powerpc: Update TM user feature bits in scan_features()" Michael Ellerman <mpe@ellerman.id.au> - 2016-05-10 03:50 +0200
[PATCH 3.19.y-ckt 02/54] [3.19-stable-only] fix backport "KVM: s390: avoid memory overwrites on emergency signal injection" Kamal Mostafa <kamal@canonical.com> - 2016-05-10 02:30 +0200
csiph-web