* [PATCH] modpost: fix buffer overflow
@ 2006-03-15 14:44 Jiri Benc
2006-03-15 14:55 ` Bernd Petrovitsch
2006-03-15 14:57 ` Bernd Petrovitsch
0 siblings, 2 replies; 9+ messages in thread
From: Jiri Benc @ 2006-03-15 14:44 UTC (permalink / raw)
To: rusty; +Cc: LKML
I got SIGABRT in modpost when building a module really deeply nested in
a filesystem (path > 100 chars):
> Building modules, stage 2.
> MODPOST
> *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size: 0x0809f588 ***
> [...]
This patch fixes that problem.
Signed-off-by: Jiri Benc <jbenc@suse.cz>
--- linux-2.6.16-rc6.orig/scripts/mod/modpost.c
+++ linux-2.6.16-rc6/scripts/mod/modpost.c
@@ -552,7 +552,7 @@ void __attribute__((format(printf, 2, 3)
va_start(ap, fmt);
len = vsnprintf(tmp, SZ, fmt, ap);
- if (buf->size - buf->pos < len + 1) {
+ while (buf->size - buf->pos < len + 1) {
buf->size += 128;
buf->p = realloc(buf->p, buf->size);
}
--
Jiri Benc
SUSE Labs
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 14:44 [PATCH] modpost: fix buffer overflow Jiri Benc
@ 2006-03-15 14:55 ` Bernd Petrovitsch
2006-03-15 14:57 ` Bernd Petrovitsch
1 sibling, 0 replies; 9+ messages in thread
From: Bernd Petrovitsch @ 2006-03-15 14:55 UTC (permalink / raw)
To: Jiri Benc; +Cc: rusty, LKML
On Wed, 2006-03-15 at 15:44 +0100, Jiri Benc wrote:
> I got SIGABRT in modpost when building a module really deeply nested in
> a filesystem (path > 100 chars):
>
> > Building modules, stage 2.
> > MODPOST
> > *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size: 0x0809f588 ***
> > [...]
>
> This patch fixes that problem.
>
> Signed-off-by: Jiri Benc <jbenc@suse.cz>
>
> --- linux-2.6.16-rc6.orig/scripts/mod/modpost.c
> +++ linux-2.6.16-rc6/scripts/mod/modpost.c
> @@ -552,7 +552,7 @@ void __attribute__((format(printf, 2, 3)
>
> va_start(ap, fmt);
> len = vsnprintf(tmp, SZ, fmt, ap);
> - if (buf->size - buf->pos < len + 1) {
> + while (buf->size - buf->pos < len + 1) {
> buf->size += 128;
> buf->p = realloc(buf->p, buf->size);
> }
Are you sure you won't pull the line with realloc() out of the loop and
do it once afterwards?
Bernd
--
Firmix Software GmbH http://www.firmix.at/
mobil: +43 664 4416156 fax: +43 1 7890849-55
Embedded Linux Development and Services
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 14:44 [PATCH] modpost: fix buffer overflow Jiri Benc
2006-03-15 14:55 ` Bernd Petrovitsch
@ 2006-03-15 14:57 ` Bernd Petrovitsch
2006-03-15 15:08 ` Jiri Benc
1 sibling, 1 reply; 9+ messages in thread
From: Bernd Petrovitsch @ 2006-03-15 14:57 UTC (permalink / raw)
To: Jiri Benc; +Cc: rusty, LKML
On Wed, 2006-03-15 at 15:44 +0100, Jiri Benc wrote:
> I got SIGABRT in modpost when building a module really deeply nested in
> a filesystem (path > 100 chars):
>
> > Building modules, stage 2.
> > MODPOST
> > *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size: 0x0809f588 ***
> > [...]
>
> This patch fixes that problem.
>
> Signed-off-by: Jiri Benc <jbenc@suse.cz>
>
> --- linux-2.6.16-rc6.orig/scripts/mod/modpost.c
> +++ linux-2.6.16-rc6/scripts/mod/modpost.c
> @@ -552,7 +552,7 @@ void __attribute__((format(printf, 2, 3)
>
> va_start(ap, fmt);
> len = vsnprintf(tmp, SZ, fmt, ap);
> - if (buf->size - buf->pos < len + 1) {
> + while (buf->size - buf->pos < len + 1) {
> buf->size += 128;
> buf->p = realloc(buf->p, buf->size);
> }
Silly me. To make it more obvious whatz I really meant was:
---- snip ----
if (buf->size - buf->pos < len + 1) {
while (buf->size - buf->pos < len + 1)
buf->size += 128;
buf->p = realloc(buf->p, buf->size);
}
---- snip ----
Bernd
--
Firmix Software GmbH http://www.firmix.at/
mobil: +43 664 4416156 fax: +43 1 7890849-55
Embedded Linux Development and Services
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 14:57 ` Bernd Petrovitsch
@ 2006-03-15 15:08 ` Jiri Benc
2006-03-15 15:35 ` Andreas Schwab
2006-03-15 22:51 ` Sam Ravnborg
0 siblings, 2 replies; 9+ messages in thread
From: Jiri Benc @ 2006-03-15 15:08 UTC (permalink / raw)
To: Bernd Petrovitsch; +Cc: rusty, LKML
On Wed, 15 Mar 2006 15:57:28 +0100, Bernd Petrovitsch wrote:
> Silly me. To make it more obvious whatz I really meant was:
> ---- snip ----
> if (buf->size - buf->pos < len + 1) {
> while (buf->size - buf->pos < len + 1)
> buf->size += 128;
> buf->p = realloc(buf->p, buf->size);
> }
> ---- snip ----
Yes, this is probably better. New version of the patch follows.
---->8----
I got SIGABRT in modpost when compiling a module really deeply nested in
a filesystem (path > 100 chars):
> Building modules, stage 2.
> MODPOST
> *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size: 0x0809f588 ***
> [...]
This patch fixes that problem.
Signed-off-by: Jiri Benc <jbenc@suse.cz>
--- linux-2.6.16-rc6.orig/scripts/mod/modpost.c
+++ linux-2.6.16-rc6/scripts/mod/modpost.c
@@ -553,7 +553,8 @@ void __attribute__((format(printf, 2, 3)
va_start(ap, fmt);
len = vsnprintf(tmp, SZ, fmt, ap);
if (buf->size - buf->pos < len + 1) {
- buf->size += 128;
+ while (buf->size - buf->pos < len + 1)
+ buf->size += 128;
buf->p = realloc(buf->p, buf->size);
}
strncpy(buf->p + buf->pos, tmp, len + 1);
--
Jiri Benc
SUSE Labs
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 15:08 ` Jiri Benc
@ 2006-03-15 15:35 ` Andreas Schwab
2006-03-15 22:51 ` Sam Ravnborg
1 sibling, 0 replies; 9+ messages in thread
From: Andreas Schwab @ 2006-03-15 15:35 UTC (permalink / raw)
To: Jiri Benc; +Cc: Bernd Petrovitsch, rusty, LKML
Jiri Benc <jbenc@suse.cz> writes:
> + while (buf->size - buf->pos < len + 1)
> + buf->size += 128;
What's wrong with
buf->size = buf->pos + len + 1;
Andreas.
--
Andreas Schwab, SuSE Labs, schwab@suse.de
SuSE Linux Products GmbH, Maxfeldstraße 5, 90409 Nürnberg, Germany
PGP key fingerprint = 58CA 54C7 6D53 942B 1756 01D3 44D5 214B 8276 4ED5
"And now for something completely different."
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 15:08 ` Jiri Benc
2006-03-15 15:35 ` Andreas Schwab
@ 2006-03-15 22:51 ` Sam Ravnborg
2006-03-16 13:21 ` Jiri Benc
1 sibling, 1 reply; 9+ messages in thread
From: Sam Ravnborg @ 2006-03-15 22:51 UTC (permalink / raw)
To: Jiri Benc; +Cc: Bernd Petrovitsch, rusty, LKML
On Wed, Mar 15, 2006 at 04:08:58PM +0100, Jiri Benc wrote:
> I got SIGABRT in modpost when compiling a module really deeply nested in
> a filesystem (path > 100 chars):
>
> > Building modules, stage 2.
> > MODPOST
> > *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size: 0x0809f588 ***
> > [...]
>
> This patch fixes that problem.
>
> Signed-off-by: Jiri Benc <jbenc@suse.cz>
>
> --- linux-2.6.16-rc6.orig/scripts/mod/modpost.c
> +++ linux-2.6.16-rc6/scripts/mod/modpost.c
> @@ -553,7 +553,8 @@ void __attribute__((format(printf, 2, 3)
> va_start(ap, fmt);
> len = vsnprintf(tmp, SZ, fmt, ap);
> if (buf->size - buf->pos < len + 1) {
> - buf->size += 128;
> + while (buf->size - buf->pos < len + 1)
> + buf->size += 128;
> buf->p = realloc(buf->p, buf->size);
> }
> strncpy(buf->p + buf->pos, tmp, len + 1);
Hi Jiri.
Can I ask you to make a new patch where you change buf_printf() to use
buf_write. And then change buf_write to allocate in chunks also.
This would be cleanest solution.
Sam
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-15 22:51 ` Sam Ravnborg
@ 2006-03-16 13:21 ` Jiri Benc
2006-03-16 15:46 ` Sam Ravnborg
2006-03-16 18:59 ` [PATCH] kbuild: fix buffer overflow in modpost Sam Ravnborg
0 siblings, 2 replies; 9+ messages in thread
From: Jiri Benc @ 2006-03-16 13:21 UTC (permalink / raw)
To: Sam Ravnborg; +Cc: Bernd Petrovitsch, rusty, LKML
On Wed, 15 Mar 2006 23:51:59 +0100, Sam Ravnborg wrote:
> Can I ask you to make a new patch where you change buf_printf() to use
> buf_write. And then change buf_write to allocate in chunks also.
> This would be cleanest solution.
This probably will be the cleanest solution, but I doubt it would be
acceptable for 2.6.16. And I think the fix should go into 2.6.16.
Thanks,
--
Jiri Benc
SUSE Labs
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] modpost: fix buffer overflow
2006-03-16 13:21 ` Jiri Benc
@ 2006-03-16 15:46 ` Sam Ravnborg
2006-03-16 18:59 ` [PATCH] kbuild: fix buffer overflow in modpost Sam Ravnborg
1 sibling, 0 replies; 9+ messages in thread
From: Sam Ravnborg @ 2006-03-16 15:46 UTC (permalink / raw)
To: Jiri Benc; +Cc: Bernd Petrovitsch, rusty, LKML
On Thu, Mar 16, 2006 at 02:21:14PM +0100, Jiri Benc wrote:
> On Wed, 15 Mar 2006 23:51:59 +0100, Sam Ravnborg wrote:
> > Can I ask you to make a new patch where you change buf_printf() to use
> > buf_write. And then change buf_write to allocate in chunks also.
> > This would be cleanest solution.
>
> This probably will be the cleanest solution, but I doubt it would be
> acceptable for 2.6.16. And I think the fix should go into 2.6.16.
Like this...
Sam
diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c
index 30f3ac8..0b92ddf 100644
--- a/scripts/mod/modpost.c
+++ b/scripts/mod/modpost.c
@@ -923,19 +923,14 @@ void __attribute__((format(printf, 2, 3)
va_start(ap, fmt);
len = vsnprintf(tmp, SZ, fmt, ap);
- if (buf->size - buf->pos < len + 1) {
- buf->size += 128;
- buf->p = realloc(buf->p, buf->size);
- }
- strncpy(buf->p + buf->pos, tmp, len + 1);
- buf->pos += len;
+ buf_write(buf, tmp, len);
va_end(ap);
}
void buf_write(struct buffer *buf, const char *s, int len)
{
if (buf->size - buf->pos < len) {
- buf->size += len;
+ buf->size += len + SZ;
buf->p = realloc(buf->p, buf->size);
}
strncpy(buf->p + buf->pos, s, len);
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH] kbuild: fix buffer overflow in modpost
2006-03-16 13:21 ` Jiri Benc
2006-03-16 15:46 ` Sam Ravnborg
@ 2006-03-16 18:59 ` Sam Ravnborg
1 sibling, 0 replies; 9+ messages in thread
From: Sam Ravnborg @ 2006-03-16 18:59 UTC (permalink / raw)
To: Jiri Benc, Linus Torvalds, Andrew Morton; +Cc: Bernd Petrovitsch, rusty, LKML
Hi Linus - please apply to 2.6.16-rc
Jiri Benc <jbenc@suse.cz> reported that modpost would stop with SIGABRT if
used with long filepaths.
The error looked like:
> Building modules, stage 2.
> MODPOST
> *** glibc detected *** scripts/mod/modpost: realloc(): invalid next size:
+0x0809f588 ***
> [...]
Following patch fixes this by allocating at least the required
memory + SZ bytes each time. Before we sometimes ended up allocating
too little memory resuting in the glibc detected bug above.
Based on patch originally submitted by: Jiri Benc <jbenc@suse.cz>
Signed-off-by: Sam Ravnborg <sam@ravnborg.org>
---
diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c
index f70ff13..b8b2a56 100644
--- a/scripts/mod/modpost.c
+++ b/scripts/mod/modpost.c
@@ -508,12 +508,7 @@ buf_printf(struct buffer *buf, const cha
va_start(ap, fmt);
len = vsnprintf(tmp, SZ, fmt, ap);
- if (buf->size - buf->pos < len + 1) {
- buf->size += 128;
- buf->p = realloc(buf->p, buf->size);
- }
- strncpy(buf->p + buf->pos, tmp, len + 1);
- buf->pos += len;
+ buf_write(buf, tmp, len);
va_end(ap);
}
@@ -521,7 +516,7 @@ void
buf_write(struct buffer *buf, const char *s, int len)
{
if (buf->size - buf->pos < len) {
- buf->size += len;
+ buf->size += len + SZ;
buf->p = realloc(buf->p, buf->size);
}
strncpy(buf->p + buf->pos, s, len);
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2006-03-16 19:00 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-03-15 14:44 [PATCH] modpost: fix buffer overflow Jiri Benc
2006-03-15 14:55 ` Bernd Petrovitsch
2006-03-15 14:57 ` Bernd Petrovitsch
2006-03-15 15:08 ` Jiri Benc
2006-03-15 15:35 ` Andreas Schwab
2006-03-15 22:51 ` Sam Ravnborg
2006-03-16 13:21 ` Jiri Benc
2006-03-16 15:46 ` Sam Ravnborg
2006-03-16 18:59 ` [PATCH] kbuild: fix buffer overflow in modpost Sam Ravnborg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®