From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Vasiliy Kulikov <segoon@openwall.com>,
Dave Airlie <airlied@redhat.com>
Subject: [23/43] agp: fix arbitrary kernel memory writes
Date: Thu, 05 May 2011 17:25:44 -0700 [thread overview]
Message-ID: <20110506002609.518405348@clark.kroah.org> (raw)
In-Reply-To: <20110506002625.GA20426@kroah.com>
2.6.33-longterm review patch. If anyone has any objections, please let us know.
------------------
From: Vasiliy Kulikov <segoon@openwall.com>
commit 194b3da873fd334ef183806db751473512af29ce upstream.
pg_start is copied from userspace on AGPIOC_BIND and AGPIOC_UNBIND ioctl
cmds of agp_ioctl() and passed to agpioc_bind_wrap(). As said in the
comment, (pg_start + mem->page_count) may wrap in case of AGPIOC_BIND,
and it is not checked at all in case of AGPIOC_UNBIND. As a result, user
with sufficient privileges (usually "video" group) may generate either
local DoS or privilege escalation.
Signed-off-by: Vasiliy Kulikov <segoon@openwall.com>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/char/agp/generic.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/drivers/char/agp/generic.c
+++ b/drivers/char/agp/generic.c
@@ -1123,8 +1123,8 @@ int agp_generic_insert_memory(struct agp
return -EINVAL;
}
- /* AK: could wrap */
- if ((pg_start + mem->page_count) > num_entries)
+ if (((pg_start + mem->page_count) > num_entries) ||
+ ((pg_start + mem->page_count) < pg_start))
return -EINVAL;
j = pg_start;
@@ -1158,7 +1158,7 @@ int agp_generic_remove_memory(struct agp
{
size_t i;
struct agp_bridge_data *bridge;
- int mask_type;
+ int mask_type, num_entries;
bridge = mem->bridge;
if (!bridge)
@@ -1170,6 +1170,11 @@ int agp_generic_remove_memory(struct agp
if (type != mem->type)
return -EINVAL;
+ num_entries = agp_num_entries();
+ if (((pg_start + mem->page_count) > num_entries) ||
+ ((pg_start + mem->page_count) < pg_start))
+ return -EINVAL;
+
mask_type = bridge->driver->agp_type_to_mask_type(bridge, type);
if (mask_type != 0) {
/* The generic routines know nothing of memory types */
next prev parent reply other threads:[~2011-05-06 0:27 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-05-06 0:26 [00/43] 2.6.33.13-longterm review Greg KH
2011-05-06 0:25 ` [01/43] ath: add missing regdomain pair 0x5c mapping Greg KH
2011-05-06 0:25 ` [02/43] block, blk-sysfs: Fix an err return path in blk_register_queue() Greg KH
2011-05-06 0:25 ` [03/43] p54: Initialize extra_len in p54_tx_80211 Greg KH
2011-05-06 0:25 ` [04/43] x86, gart: Make sure GART does not map physmem above 1TB Greg KH
2011-05-06 0:25 ` [05/43] intel-iommu: Unlink domain from iommu Greg KH
2011-05-06 0:25 ` [06/43] intel-iommu: Fix get_domain_for_dev() error path Greg KH
2011-05-06 0:25 ` [07/43] drm/radeon/kms: fix bad shift in atom iio table parser Greg KH
2011-05-06 0:25 ` [08/43] NFS: nfs_wcc_update_inode() should set nfsi->attr_gencount Greg KH
2011-05-06 0:25 ` [09/43] serial/imx: read cts state only after acking cts change irq Greg KH
2011-05-06 0:25 ` [10/43] ASoC: Fix output PGA enabling in wm_hubs CODECs Greg KH
2011-05-06 0:25 ` [11/43] kconfig: Avoid buffer underrun in choice input Greg KH
2011-05-06 0:25 ` [12/43] UBIFS: fix master node recovery Greg KH
2011-05-06 0:25 ` [13/43] Remove extra struct page member from the buffer info structure Greg KH
2011-05-06 0:25 ` [14/43] [S390] dasd: correct device table Greg KH
2011-05-06 0:25 ` [15/43] iwlagn: Support new 5000 microcode Greg KH
2011-05-06 0:25 ` [16/43] udp: Fix bogus UFO packet generation Greg KH
2011-05-06 0:25 ` [17/43] [PARISC] slub: fix panic with DISCONTIGMEM Greg KH
2011-05-06 0:25 ` [18/43] [PARISC] set memory ranges in N_NORMAL_MEMORY when onlined Greg KH
2011-05-06 0:25 ` [19/43] [media] FLEXCOP-PCI: fix __xlate_proc_name-warning for flexcop-pci Greg KH
2011-05-06 0:25 ` [20/43] m68k/mm: Set all online nodes in N_NORMAL_MEMORY Greg KH
2011-05-06 0:25 ` [21/43] nfs: dont lose MS_SYNCHRONOUS on remount of noac mount Greg KH
2011-05-06 0:25 ` [22/43] NFSv4.1: Ensure state manager thread dies on last umount Greg KH
2011-05-06 0:25 ` Greg KH [this message]
2011-05-06 0:25 ` [24/43] agp: fix OOM and buffer overflow Greg KH
2011-05-06 0:25 ` [25/43] Input: xen-kbdfront - fix mouse getting stuck after save/restore Greg KH
2011-05-06 0:25 ` [26/43] [SCSI] pmcraid: reject negative request size Greg KH
2011-05-06 0:25 ` [27/43] [SCSI] mpt2sas: prevent heap overflows and unchecked reads Greg KH
2011-05-06 0:25 ` [28/43] [SCSI] put stricter guards on queue dead checks Greg KH
2011-05-06 0:25 ` [29/43] mmc: sdhci-pci: Fix error case in sdhci_pci_probe_slot() Greg KH
2011-05-06 0:25 ` [30/43] mmc: sdhci: Check mrq->cmd in sdhci_tasklet_finish Greg KH
2011-05-06 0:25 ` [31/43] mmc: sdhci: Check mrq != NULL " Greg KH
2011-05-06 0:25 ` [32/43] USB: fix regression in usbip by setting has_tt flag Greg KH
2011-05-06 0:25 ` [33/43] x86, AMD: Fix APIC timer erratum 400 affecting K8 Rev.A-E processors Greg KH
2011-05-06 0:25 ` [34/43] af_unix: Only allow recv on connected seqpacket sockets Greg KH
2011-05-06 0:25 ` [35/43] ARM: 6891/1: prevent heap corruption in OABI semtimedop Greg KH
2011-05-06 0:25 ` [36/43] i8k: Tell gcc that *regs gets clobbered Greg KH
2011-05-06 0:25 ` [37/43] Fix gcc 4.5.1 miscompiling drivers/char/i8k.c (again) Greg KH
2011-05-06 0:25 ` [38/43] Open with O_CREAT flag set fails to open existing files on non writable directories Greg KH
2011-05-06 0:26 ` [39/43] can: Add missing socket check in can/bcm release Greg KH
2011-05-06 0:26 ` [40/43] fs/partitions/ldm.c: fix oops caused by corrupted partition table Greg KH
2011-05-06 0:26 ` [41/43] libata: set queue DMA alignment to sector size for ATAPI too Greg KH
2011-05-06 0:26 ` [42/43] usb: musb: core: set has_tt flag Greg KH
2011-05-06 0:26 ` [43/43] iwlwifi: fix skb usage after free Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110506002609.518405348@clark.kroah.org \
--to=gregkh@suse.de \
--cc=airlied@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=segoon@openwall.com \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®