From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752860AbcD1Xqj (ORCPT ); Thu, 28 Apr 2016 19:46:39 -0400 Received: from mail-pa0-f52.google.com ([209.85.220.52]:35302 "EHLO mail-pa0-f52.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752346AbcD1Xqi (ORCPT ); Thu, 28 Apr 2016 19:46:38 -0400 Date: Thu, 28 Apr 2016 16:46:36 -0700 From: Kees Cook To: linux-kernel@vger.kernel.org Cc: "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , x86@kernel.org, Kees Cook Subject: [PATCH v3] x86/boot: Warn on future overlapping memcpy() use Message-ID: <20160428234636.GA32363@www.outflux.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org If an overlapping memcpy() is ever attempted, we should report it and gracefully call memmove(). These cases can be found and fixed to use memmove() correctly, but in the meantime, we will not break booting. Suggested-by: Ingo Molnar Signed-off-by: Kees Cook --- arch/x86/boot/compressed/string.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/arch/x86/boot/compressed/string.c b/arch/x86/boot/compressed/string.c index 2befeca1aada..7402227fdfdb 100644 --- a/arch/x86/boot/compressed/string.c +++ b/arch/x86/boot/compressed/string.c @@ -8,7 +8,7 @@ #include "../string.c" #ifdef CONFIG_X86_32 -void *memcpy(void *dest, const void *src, size_t n) +static void *__memcpy(void *dest, const void *src, size_t n) { int d0, d1, d2; asm volatile( @@ -22,7 +22,7 @@ void *memcpy(void *dest, const void *src, size_t n) return dest; } #else -void *memcpy(void *dest, const void *src, size_t n) +static void *__memcpy(void *dest, const void *src, size_t n) { long d0, d1, d2; asm volatile( @@ -60,3 +60,14 @@ void *memmove(void *dest, const void *src, size_t n) return dest; } + +/* Detect and warn about potential overlaps, but handle them with memmove. */ +void *memcpy(void *dest, const void *src, size_t n) +{ + if (dest > src && dest - src < n) { + warn("Avoiding potentially unsafe overlapping memcpy()!"); + return memmove(dest, src, n); + } + return __memcpy(dest, src, n); +} + -- 2.6.3 -- Kees Cook Chrome OS & Brillo Security