From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Vasiliy Kulikov <segoon@openwall.com>,
Dave Airlie <airlied@redhat.com>
Subject: [24/43] agp: fix OOM and buffer overflow
Date: Thu, 05 May 2011 17:25:45 -0700 [thread overview]
Message-ID: <20110506002609.610411136@clark.kroah.org> (raw)
In-Reply-To: <20110506002625.GA20426@kroah.com>
2.6.33-longterm review patch. If anyone has any objections, please let us know.
------------------
From: Vasiliy Kulikov <segoon@openwall.com>
commit b522f02184b413955f3bc952e3776ce41edc6355 upstream.
page_count is copied from userspace. agp_allocate_memory() tries to
check whether this number is too big, but doesn't take into account the
wrap case. Also agp_create_user_memory() doesn't check whether
alloc_size is calculated from num_agp_pages variable without overflow.
This may lead to allocation of too small buffer with following buffer
overflow.
Another problem in agp code is not addressed in the patch - kernel memory
exhaustion (AGPIOC_RESERVE and AGPIOC_ALLOCATE ioctls). It is not checked
whether requested pid is a pid of the caller (no check in agpioc_reserve_wrap()).
Each allocation is limited to 16KB, though, there is no per-process limit.
This might lead to OOM situation, which is not even solved in case of the
caller death by OOM killer - the memory is allocated for another (faked) process.
Signed-off-by: Vasiliy Kulikov <segoon@openwall.com>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/char/agp/generic.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/char/agp/generic.c
+++ b/drivers/char/agp/generic.c
@@ -123,6 +123,9 @@ static struct agp_memory *agp_create_use
struct agp_memory *new;
unsigned long alloc_size = num_agp_pages*sizeof(struct page *);
+ if (INT_MAX/sizeof(struct page *) < num_agp_pages)
+ return NULL;
+
new = kzalloc(sizeof(struct agp_memory), GFP_KERNEL);
if (new == NULL)
return NULL;
@@ -242,11 +245,14 @@ struct agp_memory *agp_allocate_memory(s
int scratch_pages;
struct agp_memory *new;
size_t i;
+ int cur_memory;
if (!bridge)
return NULL;
- if ((atomic_read(&bridge->current_memory_agp) + page_count) > bridge->max_memory_agp)
+ cur_memory = atomic_read(&bridge->current_memory_agp);
+ if ((cur_memory + page_count > bridge->max_memory_agp) ||
+ (cur_memory + page_count < page_count))
return NULL;
if (type >= AGP_USER_TYPES) {
next prev parent reply other threads:[~2011-05-06 0:32 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-05-06 0:26 [00/43] 2.6.33.13-longterm review Greg KH
2011-05-06 0:25 ` [01/43] ath: add missing regdomain pair 0x5c mapping Greg KH
2011-05-06 0:25 ` [02/43] block, blk-sysfs: Fix an err return path in blk_register_queue() Greg KH
2011-05-06 0:25 ` [03/43] p54: Initialize extra_len in p54_tx_80211 Greg KH
2011-05-06 0:25 ` [04/43] x86, gart: Make sure GART does not map physmem above 1TB Greg KH
2011-05-06 0:25 ` [05/43] intel-iommu: Unlink domain from iommu Greg KH
2011-05-06 0:25 ` [06/43] intel-iommu: Fix get_domain_for_dev() error path Greg KH
2011-05-06 0:25 ` [07/43] drm/radeon/kms: fix bad shift in atom iio table parser Greg KH
2011-05-06 0:25 ` [08/43] NFS: nfs_wcc_update_inode() should set nfsi->attr_gencount Greg KH
2011-05-06 0:25 ` [09/43] serial/imx: read cts state only after acking cts change irq Greg KH
2011-05-06 0:25 ` [10/43] ASoC: Fix output PGA enabling in wm_hubs CODECs Greg KH
2011-05-06 0:25 ` [11/43] kconfig: Avoid buffer underrun in choice input Greg KH
2011-05-06 0:25 ` [12/43] UBIFS: fix master node recovery Greg KH
2011-05-06 0:25 ` [13/43] Remove extra struct page member from the buffer info structure Greg KH
2011-05-06 0:25 ` [14/43] [S390] dasd: correct device table Greg KH
2011-05-06 0:25 ` [15/43] iwlagn: Support new 5000 microcode Greg KH
2011-05-06 0:25 ` [16/43] udp: Fix bogus UFO packet generation Greg KH
2011-05-06 0:25 ` [17/43] [PARISC] slub: fix panic with DISCONTIGMEM Greg KH
2011-05-06 0:25 ` [18/43] [PARISC] set memory ranges in N_NORMAL_MEMORY when onlined Greg KH
2011-05-06 0:25 ` [19/43] [media] FLEXCOP-PCI: fix __xlate_proc_name-warning for flexcop-pci Greg KH
2011-05-06 0:25 ` [20/43] m68k/mm: Set all online nodes in N_NORMAL_MEMORY Greg KH
2011-05-06 0:25 ` [21/43] nfs: dont lose MS_SYNCHRONOUS on remount of noac mount Greg KH
2011-05-06 0:25 ` [22/43] NFSv4.1: Ensure state manager thread dies on last umount Greg KH
2011-05-06 0:25 ` [23/43] agp: fix arbitrary kernel memory writes Greg KH
2011-05-06 0:25 ` Greg KH [this message]
2011-05-06 0:25 ` [25/43] Input: xen-kbdfront - fix mouse getting stuck after save/restore Greg KH
2011-05-06 0:25 ` [26/43] [SCSI] pmcraid: reject negative request size Greg KH
2011-05-06 0:25 ` [27/43] [SCSI] mpt2sas: prevent heap overflows and unchecked reads Greg KH
2011-05-06 0:25 ` [28/43] [SCSI] put stricter guards on queue dead checks Greg KH
2011-05-06 0:25 ` [29/43] mmc: sdhci-pci: Fix error case in sdhci_pci_probe_slot() Greg KH
2011-05-06 0:25 ` [30/43] mmc: sdhci: Check mrq->cmd in sdhci_tasklet_finish Greg KH
2011-05-06 0:25 ` [31/43] mmc: sdhci: Check mrq != NULL " Greg KH
2011-05-06 0:25 ` [32/43] USB: fix regression in usbip by setting has_tt flag Greg KH
2011-05-06 0:25 ` [33/43] x86, AMD: Fix APIC timer erratum 400 affecting K8 Rev.A-E processors Greg KH
2011-05-06 0:25 ` [34/43] af_unix: Only allow recv on connected seqpacket sockets Greg KH
2011-05-06 0:25 ` [35/43] ARM: 6891/1: prevent heap corruption in OABI semtimedop Greg KH
2011-05-06 0:25 ` [36/43] i8k: Tell gcc that *regs gets clobbered Greg KH
2011-05-06 0:25 ` [37/43] Fix gcc 4.5.1 miscompiling drivers/char/i8k.c (again) Greg KH
2011-05-06 0:25 ` [38/43] Open with O_CREAT flag set fails to open existing files on non writable directories Greg KH
2011-05-06 0:26 ` [39/43] can: Add missing socket check in can/bcm release Greg KH
2011-05-06 0:26 ` [40/43] fs/partitions/ldm.c: fix oops caused by corrupted partition table Greg KH
2011-05-06 0:26 ` [41/43] libata: set queue DMA alignment to sector size for ATAPI too Greg KH
2011-05-06 0:26 ` [42/43] usb: musb: core: set has_tt flag Greg KH
2011-05-06 0:26 ` [43/43] iwlwifi: fix skb usage after free Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110506002609.610411136@clark.kroah.org \
--to=gregkh@suse.de \
--cc=airlied@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=segoon@openwall.com \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®