From: Joe Lawrence <joe.lawrence@redhat.com>
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: Davidlohr Bueso <dave@stgolabs.net>,
Andrea Arcangeli <aarcange@redhat.com>
Subject: Questions about commit "ipc/shm: Fix shmat mmap nil-page protection"
Date: Mon, 25 Sep 2017 15:38:07 -0400 [thread overview]
Message-ID: <472dbcaa-47b5-7a1b-7c4a-49373db784d3@redhat.com> (raw)
Hi Davidlohr,
I was looking into backporting commit 95e91b831f87 ("ipc/shm: Fix shmat
mmap nil-page protection") to a distro kernel and Andrea brought up some
interesting questions about that change.
We saw that a LTP test [1] was added some time ago to reproduce behavior
matching that of the original report [2]. However, Andrea and I are a
little confused about that original report and what the upstream commit
was intended to fix. A quick summary of our offlist discussion:
- This is only about privileged users (and no SELinux).
- We modified the 20170119_shmat_nullpage_poc.c reproducer from [2] to
include MAP_FIXED to prove (as root, no SELinux):
It is possible to mmap 0
It is NOT possible to mmap 1
- Andrea points out that mmap(1, ...) fails not because of any
mmap_min_addr checks, but for alignment reasons.
- He also wonders about other bogus addr values above 4k, but below
mmap_min_addr and whether this change misses those values
Is it possible that the original report noticed that shmat allowed
attach to an address of 1, and it was assumed that somehow mmap_min_addr
protections were circumvented? Then commit 95e91b831f87 modified the
rounding in do_shmat() so that shmat would fail on similar input (but
for apparently different reasons)?
I didn't see any discussion when looking up the original commit in the
list archives, so any explanations or pointers would be very helpful.
[1]
https://github.com/linux-test-project/ltp/blob/master/testcases/cve/cve-2017-5669.c
[2] https://bugzilla.kernel.org/show_bug.cgi?id=192931
Regards,
-- Joe
next reply other threads:[~2017-09-25 19:38 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-25 19:38 Joe Lawrence [this message]
2017-09-25 21:44 ` Andrea Arcangeli
2017-10-10 18:11 ` Joe Lawrence
2018-04-30 17:21 ` Davidlohr Bueso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=472dbcaa-47b5-7a1b-7c4a-49373db784d3@redhat.com \
--to=joe.lawrence@redhat.com \
--cc=aarcange@redhat.com \
--cc=dave@stgolabs.net \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®