From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751120AbbCTLNN (ORCPT ); Fri, 20 Mar 2015 07:13:13 -0400 Received: from mailout2.w1.samsung.com ([210.118.77.12]:10349 "EHLO mailout2.w1.samsung.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750777AbbCTLNJ (ORCPT ); Fri, 20 Mar 2015 07:13:09 -0400 X-AuditID: cbfec7f4-b7f126d000001e9a-59-550c001b77f5 From: Andrey Ryabinin To: Russell King Cc: Kees Cook , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Maria Guseva , Yury Gribov , Andrey Ryabinin , stable@vger.kernel.org Subject: [PATCH] arm: fix integer overflow in ELF_ET_DYN_BASE Date: Fri, 20 Mar 2015 14:12:52 +0300 Message-id: <1426849972-19606-1-git-send-email-a.ryabinin@samsung.com> X-Mailer: git-send-email 2.3.3 X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrNJMWRmVeSWpSXmKPExsVy+t/xa7rSDDyhBu8+cFps+/WIzeJMd67F psfXWC0u75rDZnH7Mq/FgjvfmSwWbHzEaHHo82ImBw6PluYeNo/ZDRdZPDYvqffo27KK0ePz JrkA1igum5TUnMyy1CJ9uwSujOcblzEXHOOrOHBkJ0sD43/uLkYODgkBE4kF5zK6GDmBTDGJ C/fWs4HYQgJLGSU+TtOCsPuYJA7MNASx2QT0JP7N2g5WIyKgKXFq8UXmLkYuDmaBX4wSE+58 YAOZKSxgKzFnpyxIDYuAqsTWpWfZQcK8Am4SnavqILbKSSx8Lz6BkXsBI8MqRtHU0uSC4qT0 XEO94sTc4tK8dL3k/NxNjJAA+bKDcfExq0OMAhyMSjy8P3dzhwqxJpYVV+YeYpTgYFYS4ZX6 AxTiTUmsrEotyo8vKs1JLT7EyMTBKdXAGLv56eN7R9JnR/84tvfJ389N3cn+32/NUq36wXDf 7bREoHO8465XcXsdL0b9Sb7DMVU66F7bZV3thjcxE5Yk6cpcWTnz32s97cyYmZI/pr2cp9Vr /76p6XX5WS23rDthQseYhdZYRcyd99YqrTzFSHsB43kRs6Onxesamk6LefSWLNNKUEs2UmIp zkg01GIuKk4EADeVfkLuAQAA Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Usually ELF_ET_DYN_BASE is 2/3 of TASK_SIZE. With 3G/1G user/kernel split this is not so, because 2*TASK_SIZE overflows 32 bits, so the actual value of ELF_ET_DYN_BASE is: (2 * TASK_SIZE / 3) = 0x2a000000 When ASLR is disabled PIE binaries will load at ELF_ET_DYN_BASE address. On 32bit platforms AddressSanitzer uses addresses [0x20000000 - 0x40000000] for shadow memory [1]. So ASan doesn't work for PIE binaries when ASLR disabled as it fails to map shadow memory. Also after Kees's 'split ET_DYN ASLR from mmap ASLR' patchset PIE binaries has a high chance of loading somewhere in between [0x2a000000 - 0x40000000] even if ASLR enabled. This makes ASan with PIE absolutely incompatible. Fix overflow by dividing TASK_SIZE prior to multiplying. After this patch ELF_ET_DYN_BASE equals to (for CONFIG_VMSPLIT_3G=y): (TASK_SIZE / 3 * 2) = 0x7f555554 [1] https://code.google.com/p/address-sanitizer/wiki/AddressSanitizerAlgorithm#Mapping Signed-off-by: Andrey Ryabinin Reported-by: Maria Guseva Cc: stable@vger.kernel.org --- arch/arm/include/asm/elf.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm/include/asm/elf.h b/arch/arm/include/asm/elf.h index c1ff8ab..1984a92 100644 --- a/arch/arm/include/asm/elf.h +++ b/arch/arm/include/asm/elf.h @@ -115,7 +115,7 @@ int dump_task_regs(struct task_struct *t, elf_gregset_t *elfregs); the loader. We need to make sure that it is out of the way of the program that it will "exec", and that there is sufficient room for the brk. */ -#define ELF_ET_DYN_BASE (2 * TASK_SIZE / 3) +#define ELF_ET_DYN_BASE (TASK_SIZE / 3 * 2) /* When the program starts, a1 contains a pointer to a function to be registered with atexit, as per the SVR4 ABI. A value of 0 means we -- 2.3.3