mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: [-mm patch] binfmt_elf: fix checks for bad address
@ 2006-06-21 12:24 Chuck Ebbert
  2006-06-22  1:06 ` Ernie Petrides
  0 siblings, 1 reply; 4+ messages in thread
From: Chuck Ebbert @ 2006-06-21 12:24 UTC (permalink / raw)
  To: Andrew Morton; +Cc: torvalds, linux-kernel

In-Reply-To: <20060619222512.58ba3e48.akpm@osdl.org>

On Mon, 19 Jun 2006 22:25:12 -0700, Andrew Morton wrote:

> On Tue, 20 Jun 2006 00:55:24 -0400
> Chuck Ebbert <76306.1226@compuserve.com> wrote:
> 
> > -#define BAD_ADDR(x) ((unsigned long)(x) > TASK_SIZE)
> > +#define BAD_ADDR(x) ((unsigned long)(x) >= TASK_SIZE)
>
> Convince us that this is correct for all the other users of BAD_ADDR() in
> this file.

Can I just wave my arms while asserting it's obvious?  It seemed that
way to me...

There are two more logical pieces to that patch in RHEL4 but those I
really didn't understand enough to post. Who's the binfmt_elf expert?

-- 
Chuck
 "You can't read a newspaper if you can't read."  --George W. Bush

^ permalink raw reply	[flat|nested] 4+ messages in thread
* [-mm patch] binfmt_elf: fix checks for bad address
@ 2006-06-20  4:55 Chuck Ebbert
  2006-06-20  5:25 ` Andrew Morton
  0 siblings, 1 reply; 4+ messages in thread
From: Chuck Ebbert @ 2006-06-20  4:55 UTC (permalink / raw)
  To: linux-kernel; +Cc: Andrew Morton, Linus Torvalds

Fix check for bad address; use macro instead of open-coding two checks.

Taken from RHEL4 kernel update.

Signed-off-by: Chuck Ebbert <76306.1226@compuserve.com>

--- 2.6.17-32.orig/fs/binfmt_elf.c
+++ 2.6.17-32/fs/binfmt_elf.c
@@ -84,7 +84,7 @@ static struct linux_binfmt elf_format = 
 		.min_coredump	= ELF_EXEC_PAGESIZE
 };
 
-#define BAD_ADDR(x) ((unsigned long)(x) > TASK_SIZE)
+#define BAD_ADDR(x) ((unsigned long)(x) >= TASK_SIZE)
 
 static int set_brk(unsigned long start, unsigned long end)
 {
@@ -394,7 +394,7 @@ static unsigned long load_elf_interp(str
 			 * <= p_memsize so it's only necessary to check p_memsz.
 			 */
 			k = load_addr + eppnt->p_vaddr;
-			if (k > TASK_SIZE ||
+			if (BAD_ADDR(k) ||
 			    eppnt->p_filesz > eppnt->p_memsz ||
 			    eppnt->p_memsz > TASK_SIZE ||
 			    TASK_SIZE - eppnt->p_memsz < k) {
@@ -888,7 +888,7 @@ static int load_elf_binary(struct linux_
 		 * allowed task size. Note that p_filesz must always be
 		 * <= p_memsz so it is only necessary to check p_memsz.
 		 */
-		if (k > TASK_SIZE || elf_ppnt->p_filesz > elf_ppnt->p_memsz ||
+		if (BAD_ADDR(k) || elf_ppnt->p_filesz > elf_ppnt->p_memsz ||
 		    elf_ppnt->p_memsz > TASK_SIZE ||
 		    TASK_SIZE - elf_ppnt->p_memsz < k) {
 			/* set_brk can never work. Avoid overflows. */
-- 
Chuck
 "You can't read a newspaper if you can't read."  --George W. Bush

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2006-06-22  1:03 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-06-21 12:24 [-mm patch] binfmt_elf: fix checks for bad address Chuck Ebbert
2006-06-22  1:06 ` Ernie Petrides
  -- strict thread matches above, loose matches on Subject: below --
2006-06-20  4:55 Chuck Ebbert
2006-06-20  5:25 ` Andrew Morton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®