Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1464831
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! |
| Date | 2016-08-18 00:00 +0200 |
| Message-ID | <s7h2p-73u-7@gated-at.bofh.it> (permalink) |
| References | <s77Z7-TF-9@gated-at.bofh.it> <s7bJo-3pe-19@gated-at.bofh.it> <s7gSK-6Zu-13@gated-at.bofh.it> <s7h2p-73u-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Aug 17, 2016 at 2:45 PM, Linus Torvalds <torvalds@linux-foundation.org> wrote: > On Wed, Aug 17, 2016 at 2:37 PM, Rik van Riel <riel@redhat.com> wrote: >> >> This particular allocation is through kmalloc, but the >> kernel in question has CONFIG_SLOB=y, and usercopy has >> no code in mm/slob.c > > Oh, I didn't notice that. > > Maybe we can just say that HARDENING depends on !SLOB for now, and see > if anything else shows up. This logic (for avoiding uninstrumented allocators, which is only SLOB) already exists (via CONFIG_HAVE_HARDENED_USERCOPY_ALLOCATOR). And PageSlab(page) should be catching this, so that the logic of "this is from the allocator, so we must use its checker" is supposed to get invoked. > Maybe we don't have any code that copies data from (non-kmalloc) > multi-order allocations to user space. > > Networking does, but seems to use __GFP_COMP, at least in the one case > I checked (skbuff). Was this allocation really through kmalloc? -Kees -- Kees Cook Nexus Security
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-17 18:20 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-17 23:30 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-17 23:40 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-17 23:40 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Rik van Riel <riel@redhat.com> - 2016-08-17 23:50 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Linus Torvalds <torvalds@linux-foundation.org> - 2016-08-18 00:00 +0200
Re: [x86/uaccess] 5b710f34e1: kernel BUG at mm/usercopy.c:75! Kees Cook <keescook@chromium.org> - 2016-08-18 00:00 +0200
csiph-web