mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	Pavel Emelyanov <xemul@openvz.org>
Subject: [18/26] next_pidmap: fix overflow condition
Date: Tue, 19 Apr 2011 14:02:34 -0700	[thread overview]
Message-ID: <20110419210324.191919601@clark.kroah.org> (raw)
In-Reply-To: <20110419210333.GA17417@kroah.com>

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain, Size: 2291 bytes --]

2.6.33-longterm review patch.  If anyone has any objections, please let us know.

------------------

From: Linus Torvalds <torvalds@linux-foundation.org>

commit c78193e9c7bcbf25b8237ad0dec82f805c4ea69b upstream.

next_pidmap() just quietly accepted whatever 'last' pid that was passed
in, which is not all that safe when one of the users is /proc.

Admittedly the proc code should do some sanity checking on the range
(and that will be the next commit), but that doesn't mean that the
helper functions should just do that pidmap pointer arithmetic without
checking the range of its arguments.

So clamp 'last' to PID_MAX_LIMIT.  The fact that we then do "last+1"
doesn't really matter, the for-loop does check against the end of the
pidmap array properly (it's only the actual pointer arithmetic overflow
case we need to worry about, and going one bit beyond isn't going to
overflow).

[ Use PID_MAX_LIMIT rather than pid_max as per Eric Biederman ]

Reported-by: Tavis Ormandy <taviso@cmpxchg8b.com>
Analyzed-by: Robert Święcki <robert@swiecki.net>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Cc: Pavel Emelyanov <xemul@openvz.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 include/linux/pid.h |    2 +-
 kernel/pid.c        |    5 ++++-
 2 files changed, 5 insertions(+), 2 deletions(-)

--- a/include/linux/pid.h
+++ b/include/linux/pid.h
@@ -117,7 +117,7 @@ extern struct pid *find_vpid(int nr);
  */
 extern struct pid *find_get_pid(int nr);
 extern struct pid *find_ge_pid(int nr, struct pid_namespace *);
-int next_pidmap(struct pid_namespace *pid_ns, int last);
+int next_pidmap(struct pid_namespace *pid_ns, unsigned int last);
 
 extern struct pid *alloc_pid(struct pid_namespace *ns);
 extern void free_pid(struct pid *pid);
--- a/kernel/pid.c
+++ b/kernel/pid.c
@@ -183,11 +183,14 @@ static int alloc_pidmap(struct pid_names
 	return -1;
 }
 
-int next_pidmap(struct pid_namespace *pid_ns, int last)
+int next_pidmap(struct pid_namespace *pid_ns, unsigned int last)
 {
 	int offset;
 	struct pidmap *map, *end;
 
+	if (last >= PID_MAX_LIMIT)
+		return -1;
+
 	offset = (last + 1) & BITS_PER_PAGE_MASK;
 	map = &pid_ns->pidmap[(last + 1)/BITS_PER_PAGE];
 	end = &pid_ns->pidmap[PIDMAP_ENTRIES];



  parent reply	other threads:[~2011-04-19 21:06 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-04-19 21:03 [00/26] 2.6.33.12-longterm review Greg KH
2011-04-19 21:02 ` [01/26] cifs: always do is_path_accessible check in cifs_mount Greg KH
2011-04-19 21:02 ` [02/26] [media] video: sn9c102: world-wirtable sysfs files Greg KH
2011-04-19 21:02 ` [03/26] UBIFS: restrict world-writable debugfs files Greg KH
2011-04-19 21:02 ` [04/26] NET: cdc-phonet, handle empty phonet header Greg KH
2011-04-19 21:02 ` [05/26] x86: Fix a bogus unwind annotation in lib/semaphore_32.S Greg KH
2011-04-19 21:02 ` [06/26] [IA64] tioca: Fix assignment from incompatible pointer warnings Greg KH
2011-04-19 21:02 ` [07/26] [IA64] mca.c: Fix cast from integer to pointer warning Greg KH
2011-04-19 21:02 ` [08/26] ramfs: fix memleak on no-mmu arch Greg KH
2011-04-19 21:02 ` [09/26] MAINTAINERS: update STABLE BRANCH info Greg KH
2011-04-19 21:02 ` [10/26] UBIFS: fix oops when R/O file-system is fsynced Greg KH
2011-04-19 21:02 ` [11/26] x86, AMD: Set ARAT feature on AMD processors Greg KH
2011-04-19 21:02 ` [12/26] x86, cpu: AMD errata checking framework Greg KH
2011-04-19 21:02 ` [13/26] x86, cpu: Clean up AMD erratum 400 workaround Greg KH
2011-04-19 21:02 ` [14/26] x86, amd: Disable GartTlbWlkErr when BIOS forgets it Greg KH
2011-04-19 21:02 ` [15/26] USB: ftdi_sio: Added IDs for CTI USB Serial Devices Greg KH
2011-04-19 21:02 ` [16/26] USB: ftdi_sio: add PID for OCT DK201 docking station Greg KH
2011-04-19 21:02 ` [17/26] USB: ftdi_sio: add ids for Hameg HO720 and HO730 Greg KH
2011-04-19 21:02 ` Greg KH [this message]
2011-04-19 21:02 ` [19/26] proc: do proper range check on readdir offset Greg KH
2011-04-19 21:02 ` [20/26] USB: EHCI: unlink unused QHs when the controller is stopped Greg KH
2011-04-19 21:02 ` [21/26] USB: fix formatting of SuperSpeed endpoints in /proc/bus/usb/devices Greg KH
2011-04-19 21:02 ` [22/26] USB: xhci - fix unsafe macro definitions Greg KH
2011-04-19 21:02 ` [23/26] USB: xhci - fix math in xhci_get_endpoint_interval() Greg KH
2011-04-19 21:02 ` [24/26] x86, cpu: Fix regression in AMD errata checking code Greg KH
2011-04-19 21:02 ` [25/26] net: ax25: fix information leak to userland harder Greg KH
2011-04-19 21:02 ` [26/26] net: fix rds_iovec page count overflow Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110419210324.191919601@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=ebiederm@xmission.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=xemul@openvz.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®