From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752458AbdGaNjq (ORCPT ); Mon, 31 Jul 2017 09:39:46 -0400 Received: from mail.kernel.org ([198.145.29.99]:51562 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752164AbdGaNjo (ORCPT ); Mon, 31 Jul 2017 09:39:44 -0400 DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 3E6BD22C86 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=kernel.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=mhiramat@kernel.org From: Masami Hiramatsu To: Ingo Molnar Cc: Ingo Molnar , "H . Peter Anvin" , x86@kernel.org, Masami Hiramatsu , Ananth N Mavinakayanahalli , Anil S Keshavamurthy , "David S . Miller" , linux-kernel@vger.kernel.org Subject: [PATCH -tip 1/2] kprobes/x86: Don't forget to set memory back to RO on failure Date: Mon, 31 Jul 2017 22:38:55 +0900 Message-Id: <150150832476.31981.15380750058308167313.stgit@devbox> X-Mailer: git-send-email 2.13.3 In-Reply-To: <150150825899.31981.16898805685027748636.stgit@devbox> References: <150150825899.31981.16898805685027748636.stgit@devbox> User-Agent: StGit/0.17.1-dirty MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Do not forget to set kprobes insn buffer memory back to RO on failure path. Without this fix, if there is an unexpected error on copying instructions, kprobes insn buffer kept RW, which can allow unexpected modifying instruction buffer. Fixes: d0381c81c2f7 ("kprobes/x86: Set kprobes pages read-only") Signed-off-by: Masami Hiramatsu --- arch/x86/kernel/kprobes/core.c | 4 +++- arch/x86/kernel/kprobes/opt.c | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/arch/x86/kernel/kprobes/core.c b/arch/x86/kernel/kprobes/core.c index f0153714ddac..b16b10114e20 100644 --- a/arch/x86/kernel/kprobes/core.c +++ b/arch/x86/kernel/kprobes/core.c @@ -435,8 +435,10 @@ static int arch_copy_kprobe(struct kprobe *p) /* Copy an instruction with recovering if other optprobe modifies it.*/ len = __copy_instruction(p->ainsn.insn, p->addr, &insn); - if (!len) + if (!len) { + set_memory_ro((unsigned long)p->ainsn.insn & PAGE_MASK, 1); return -EINVAL; + } /* * __copy_instruction can modify the displacement of the instruction, diff --git a/arch/x86/kernel/kprobes/opt.c b/arch/x86/kernel/kprobes/opt.c index 69ea0bc1cfa3..853614560a4f 100644 --- a/arch/x86/kernel/kprobes/opt.c +++ b/arch/x86/kernel/kprobes/opt.c @@ -368,6 +368,7 @@ int arch_prepare_optimized_kprobe(struct optimized_kprobe *op, ret = copy_optimized_instructions(buf + TMPL_END_IDX, op->kp.addr); if (ret < 0) { __arch_remove_optimized_kprobe(op, 0); + set_memory_ro((unsigned long)buf & PAGE_MASK, 1); return ret; } op->optinsn.size = ret;