From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932128AbbGYOiL (ORCPT ); Sat, 25 Jul 2015 10:38:11 -0400 Received: from mout.kundenserver.de ([212.227.126.130]:64830 "EHLO mout.kundenserver.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932081AbbGYOiK (ORCPT ); Sat, 25 Jul 2015 10:38:10 -0400 From: Benjamin Randazzo To: neilb@suse.com Cc: linux-raid@vger.kernel.org, linux-kernel@vger.kernel.org, Benjamin Randazzo Subject: [PATCH] drivers/md/md.c: use kzalloc() when bitmap is disabled Date: Sat, 25 Jul 2015 16:36:50 +0200 Message-Id: <1437835010-11430-1-git-send-email-benjamin@randazzo.fr> X-Mailer: git-send-email 2.3.6 X-Provags-ID: V03:K0:2A2vDAKCbayBTLi2rpQhgj91rYc3luebR/sXqUhMyB1UYgjv7hs 0HNPyj08xzB+yPpPg+ZFOhFt0+4EMtH/EmzGG+uYY1itZe45ljk3JLtG+6QcL8e4cD4xJ4j J43z65SS0n4+xzQnvt5ei3amS5JKmeREEWssE0EuFylZRsT82fUsmsdDlf5CZktoJQfN7Ai thoXVuFSLU3qFLR2Cs2fQ== X-UI-Out-Filterresults: notjunk:1;V01:K0:PXnZ3CRXCi4=:K302h3SKSFxSjKt64ujZ9w awJlEokqB03pB9JcnUZrRibFUUENtuDeMFIGow4CrBSL3UhS5uUznELMMwfoQa/4CTxz7DfEl sboJM/B0prKBhiJUl8Pfyc1pM+4W7j/D/I0X9LV9gklDo17uoH6wDGeIQ2e99Dhc7Z8YMTEIY QFgzESy+ZuHXTBxAoBvE6K1p2M5y31MTmtD5V5mWEzrrQyczQrcjIzLR+qIsEdVjjGuFr3mP8 CeepBubQSfVq7N1sk3E371a74I13vZsXy0g3gwzEH7JaeK5A0bs7q+OOjtiO793Hyo0CDcY41 fOuLe3a1bTZUGXC/3WzPl7Dxs5ydQTcwFqlWmioKlX6AAbd4GmOe7HYt4HNdPTL5elhWZ2zRF m0u5bZfcjDQiyyk5HR6UKh0ehPp/ccvpVud5zfilPiJ0QLRnrebuSB8+zFv5EUgWNmzE9oCgb cKqh9QIvI+1DBDAhmRY9SVMYXHzQzvrdFAnwVaHpVfovBbrNSAf4JSCpPHJGFPe/dIdlj0Lh3 oB6USx2j7H95VJg2OTfnOYl1qgDACGJyP8zwVzgCHPkeTiFNrYWfMnSg7AxVyiB+TPrExI9sn WGTQngewCbv5Dbu9xv0lGpIVViw2+CpxVoju3Vi9yIcbUL5wGZVb//rejYctAwv99jH0W+uKB 0QlaE9td/uq6pczQhrq4MAj+a Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In drivers/md/md.c get_bitmap_file() uses kmalloc() for creating a mdu_bitmap_file_t called "file". 5769 file = kmalloc(sizeof(*file), GFP_NOIO); 5770 if (!file) 5771 return -ENOMEM; This structure is copied to user space at the end of the function. 5786 if (err == 0 && 5787 copy_to_user(arg, file, sizeof(*file))) 5788 err = -EFAULT But if bitmap is disabled only the first byte of "file" is initialized with zero, so it's possible to read some bytes (up to 4095) of kernel space memory from user space. This is an information leak. 5775 /* bitmap disabled, zero the first byte and copy out */ 5776 if (!mddev->bitmap_info.file) 5777 file->pathname[0] = '\0'; Signed-off-by: Benjamin Randazzo --- drivers/md/md.c | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/drivers/md/md.c b/drivers/md/md.c index 80879dc..382bdbc 100644 --- a/drivers/md/md.c +++ b/drivers/md/md.c @@ -5766,22 +5766,21 @@ static int get_bitmap_file(struct mddev *mddev, void __user * arg) char *ptr; int err; - file = kmalloc(sizeof(*file), GFP_NOIO); + file = kzalloc(sizeof(*file), GFP_NOIO); if (!file) return -ENOMEM; err = 0; spin_lock(&mddev->lock); - /* bitmap disabled, zero the first byte and copy out */ - if (!mddev->bitmap_info.file) - file->pathname[0] = '\0'; - else if ((ptr = file_path(mddev->bitmap_info.file, - file->pathname, sizeof(file->pathname))), - IS_ERR(ptr)) - err = PTR_ERR(ptr); - else - memmove(file->pathname, ptr, - sizeof(file->pathname)-(ptr-file->pathname)); + /* bitmap enabled */ + if (mddev->bitmap_info.file) { + if ((ptr = file_path(mddev->bitmap_info.file, file->pathname, + sizeof(file->pathname))), IS_ERR(ptr)) + err = PTR_ERR(ptr); + else + memmove(file->pathname, ptr, + sizeof(file->pathname)-(ptr-file->pathname)); + } spin_unlock(&mddev->lock); if (err == 0 && -- 2.3.6