From: "Tobin C. Harding" <me@tobin.cc>
To: me@tobin.cc, kaiwan.billimoria@gmail.com
Cc: "Kirill A. Shutemov" <kirill@shutemov.name>,
Alexander Kapshuk <alexander.kapshuk@gmail.com>,
LKML <linux-kernel@vger.kernel.org>,
kernel-hardening@lists.openwall.com
Subject: [PATCH 3/5] leaking_addresses: add range check for vsyscall memory
Date: Thu, 7 Dec 2017 15:32:23 +1100 [thread overview]
Message-ID: <1512621145-4783-4-git-send-email-me@tobin.cc> (raw)
In-Reply-To: <1512621145-4783-1-git-send-email-me@tobin.cc>
Currently script checks only first and last address in the vsyscall
memory range. We can do better than this.
When checking for false positives against $match, convert $match to
a hexadecimal value then check if it lies within the range of vsyscall
addresses.
Signed-off-by: Tobin C. Harding <me@tobin.cc>
---
scripts/leaking_addresses.pl | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/scripts/leaking_addresses.pl b/scripts/leaking_addresses.pl
index 066c609b1adb..cb69ccd4153a 100755
--- a/scripts/leaking_addresses.pl
+++ b/scripts/leaking_addresses.pl
@@ -20,6 +20,7 @@ use Cwd 'abs_path';
use Term::ANSIColor qw(:constants);
use Getopt::Long qw(:config no_auto_abbrev);
use Config;
+use bigint qw/hex/;
my $P = $0;
my $V = '0.01';
@@ -196,17 +197,24 @@ sub is_false_positive
return 1;
}
- if (is_x86_64()) {
- # vsyscall memory region, we should probably check against a range here.
- if ($match =~ '\bf{10}600000\b' or
- $match =~ '\bf{10}601000\b') {
- return 1;
- }
+ if (is_x86_64() and is_in_vsyscall_memory_region($match)) {
+ return 1;
}
return 0;
}
+sub is_in_vsyscall_memory_region
+{
+ my ($match) = @_;
+
+ my $hex = hex($match);
+ my $region_min = hex("0xffffffffff600000");
+ my $region_max = hex("0xffffffffff601000");
+
+ return ($hex >= $region_min and $hex <= $region_max);
+}
+
# True if argument potentially contains a kernel address.
sub may_leak_address
{
--
2.7.4
next prev parent reply other threads:[~2017-12-07 4:33 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-12-07 4:32 [PATCH 0/5] leaking_addresses: support 5 page table level Tobin C. Harding
2017-12-07 4:32 ` [PATCH 1/5] leaking_addresses: remove command examples Tobin C. Harding
2017-12-07 4:32 ` [PATCH 2/5] leaking_addresses: indent dependant options Tobin C. Harding
2017-12-07 4:32 ` Tobin C. Harding [this message]
2017-12-07 4:32 ` [PATCH 4/5] leaking_addresses: add support for kernel config file Tobin C. Harding
2017-12-08 1:55 ` Kaiwan N Billimoria
2017-12-07 4:32 ` [PATCH 5/5] leaking_addresses: add support for 5 page table levels Tobin C. Harding
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1512621145-4783-4-git-send-email-me@tobin.cc \
--to=me@tobin.cc \
--cc=alexander.kapshuk@gmail.com \
--cc=kaiwan.billimoria@gmail.com \
--cc=kernel-hardening@lists.openwall.com \
--cc=kirill@shutemov.name \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®