mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] fix mmap random address range on x86
@ 2011-02-18 13:15 Ludwig Nussel
  2011-02-28 23:18 ` [Security] " Andrew Morton
  0 siblings, 1 reply; 3+ messages in thread
From: Ludwig Nussel @ 2011-02-18 13:15 UTC (permalink / raw)
  To: linux-kernel
  Cc: x86, Ingo Molnar, Thomas Gleixner, H. Peter Anvin, security,
	Ludwig Nussel

On x86 casting the unsigned int result of get_random_int() to long
may result in a negative value. On x86 the range of mmap_rnd()
therefore was -255 to 255. The 32bit mode on x86_64 used 0 to 255 as
intended.

The bug was introduced by commit 675a081 in January 2008.

Signed-off-by: Ludwig Nussel <ludwig.nussel@suse.de>
---
 arch/x86/mm/mmap.c |    4 ++--
 1 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/mm/mmap.c b/arch/x86/mm/mmap.c
index 1dab519..f927429 100644
--- a/arch/x86/mm/mmap.c
+++ b/arch/x86/mm/mmap.c
@@ -87,9 +87,9 @@ static unsigned long mmap_rnd(void)
 	*/
 	if (current->flags & PF_RANDOMIZE) {
 		if (mmap_is_ia32())
-			rnd = (long)get_random_int() % (1<<8);
+			rnd = get_random_int() % (1<<8);
 		else
-			rnd = (long)(get_random_int() % (1<<28));
+			rnd = get_random_int() % (1<<28);
 	}
 	return rnd << PAGE_SHIFT;
 }
-- 
1.7.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2011-03-01  8:41 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2011-02-18 13:15 [PATCH] fix mmap random address range on x86 Ludwig Nussel
2011-02-28 23:18 ` [Security] " Andrew Morton
2011-03-01  8:41   ` Ludwig Nussel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®