mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] Fix kernel information leak with print-fatal-signals=1
@ 2009-12-25 20:29 Andi Kleen
  0 siblings, 0 replies; only message in thread
From: Andi Kleen @ 2009-12-25 20:29 UTC (permalink / raw)
  To: akpm, linux-kernel, mingo; +Cc: stable

Fix kernel information leak with print-fatal-signals=1

When print-fatal-signals is enabled it's possible to dump
any memory reachable by the kernel to the log by simply jumping to
that address from user space. 

Or crash the system if there's some hardware with read
side effects.

The fatal signals handler will dump 16 bytes at the execution 
address, which is fully controlled by ring 3.

In addition when something jumps to a unmapped address there
will be up to 16 additional useless page faults, which might be potentially
slow (and at least is not very efficient)

Fortunately this option is off by default and only there on i386.

But fix it by checking for kernel addresses and also stopping
when there's a page fault.

Stable candidate.

Signed-off-by: Andi Kleen <ak@linux.intel.com>

---
 kernel/signal.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

Index: linux-2.6.33-rc1-ak/kernel/signal.c
===================================================================
--- linux-2.6.33-rc1-ak.orig/kernel/signal.c
+++ linux-2.6.33-rc1-ak/kernel/signal.c
@@ -979,7 +979,8 @@ static void print_fatal_signal(struct pt
 		for (i = 0; i < 16; i++) {
 			unsigned char insn;
 
-			__get_user(insn, (unsigned char *)(regs->ip + i));
+			if (get_user(insn, (unsigned char *)(regs->ip + i)))
+				break;
 			printk("%02x ", insn);
 		}
 	}

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2009-12-25 20:30 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-12-25 20:29 [PATCH] Fix kernel information leak with print-fatal-signals=1 Andi Kleen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome