Kirill A. Shutemov
bfd40eaff5
mm: fix vma_is_anonymous() false-positives
...
vma_is_anonymous() relies on ->vm_ops being NULL to detect anonymous
VMA. This is unreliable as ->mmap may not set ->vm_ops.
False-positive vma_is_anonymous() may lead to crashes:
next ffff8801ce5e7040 prev ffff8801d20eca50 mm ffff88019c1e13c0
prot 27 anon_vma ffff88019680cdd8 vm_ops 0000000000000000
pgoff 0 file ffff8801b2ec2d00 private_data 0000000000000000
flags: 0xff(read|write|exec|shared|mayread|maywrite|mayexec|mayshare)
------------[ cut here ]------------
kernel BUG at mm/memory.c:1422!
invalid opcode: 0000 [#1 ] SMP KASAN
CPU: 0 PID: 18486 Comm: syz-executor3 Not tainted 4.18.0-rc3+ #136
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google
01/01/2011
RIP: 0010:zap_pmd_range mm/memory.c:1421 [inline]
RIP: 0010:zap_pud_range mm/memory.c:1466 [inline]
RIP: 0010:zap_p4d_range mm/memory.c:1487 [inline]
RIP: 0010:unmap_page_range+0x1c18/0x2220 mm/memory.c:1508
Call Trace:
unmap_single_vma+0x1a0/0x310 mm/memory.c:1553
zap_page_range_single+0x3cc/0x580 mm/memory.c:1644
unmap_mapping_range_vma mm/memory.c:2792 [inline]
unmap_mapping_range_tree mm/memory.c:2813 [inline]
unmap_mapping_pages+0x3a7/0x5b0 mm/memory.c:2845
unmap_mapping_range+0x48/0x60 mm/memory.c:2880
truncate_pagecache+0x54/0x90 mm/truncate.c:800
truncate_setsize+0x70/0xb0 mm/truncate.c:826
simple_setattr+0xe9/0x110 fs/libfs.c:409
notify_change+0xf13/0x10f0 fs/attr.c:335
do_truncate+0x1ac/0x2b0 fs/open.c:63
do_sys_ftruncate+0x492/0x560 fs/open.c:205
__do_sys_ftruncate fs/open.c:215 [inline]
__se_sys_ftruncate fs/open.c:213 [inline]
__x64_sys_ftruncate+0x59/0x80 fs/open.c:213
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
Reproducer:
#include <stdio.h>
#include <stddef.h>
#include <stdint.h>
#include <stdlib.h>
#include <string.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/ioctl.h>
#include <sys/mman.h>
#include <unistd.h>
#include <fcntl.h>
#define KCOV_INIT_TRACE _IOR('c', 1, unsigned long)
#define KCOV_ENABLE _IO('c', 100)
#define KCOV_DISABLE _IO('c', 101)
#define COVER_SIZE (1024<<10)
#define KCOV_TRACE_PC 0
#define KCOV_TRACE_CMP 1
int main(int argc, char **argv)
{
int fd;
unsigned long *cover;
system("mount -t debugfs none /sys/kernel/debug");
fd = open("/sys/kernel/debug/kcov", O_RDWR);
ioctl(fd, KCOV_INIT_TRACE, COVER_SIZE);
cover = mmap(NULL, COVER_SIZE * sizeof(unsigned long),
PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);
munmap(cover, COVER_SIZE * sizeof(unsigned long));
cover = mmap(NULL, COVER_SIZE * sizeof(unsigned long),
PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
memset(cover, 0, COVER_SIZE * sizeof(unsigned long));
ftruncate(fd, 3UL << 20);
return 0;
}
This can be fixed by assigning anonymous VMAs own vm_ops and not relying
on it being NULL.
If ->mmap() failed to set ->vm_ops, mmap_region() will set it to
dummy_vm_ops. This way we will have non-NULL ->vm_ops for all VMAs.
Link: http://lkml.kernel.org/r/20180724121139.62570-4-kirill.shutemov@linux.intel.com
Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: syzbot+3f84280d52be9b7083cc@syzkaller.appspotmail.com
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Dmitry Vyukov <dvyukov@google.com>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2018-07-26 19:38:03 -07:00
..
2018-06-12 16:19:22 -07:00
2018-06-15 07:31:07 +09:00
2018-05-28 12:36:41 +02:00
2018-06-16 16:32:04 +09:00
2018-07-14 11:11:09 -07:00
2018-06-15 18:10:01 -03:00
2018-05-22 14:27:50 -04:00
2018-07-21 16:42:03 -07:00
2018-07-25 14:49:00 +01:00
2018-06-26 18:42:44 +02:00
2018-07-05 13:48:25 -05:00
2018-06-05 16:57:31 -07:00
2018-06-05 16:57:31 -07:00
2018-06-15 07:31:07 +09:00
2018-06-11 10:16:13 -07:00
2018-06-12 20:52:16 -07:00
2018-03-14 13:31:23 +01:00
2018-06-12 16:19:22 -07:00
2018-05-26 09:16:25 +02:00
2018-06-15 07:55:24 +09:00
2018-04-12 12:04:49 +02:00
2018-06-20 11:04:26 +02:00
2018-07-08 11:10:30 -07:00
2018-06-15 07:31:07 +09:00
2018-07-21 12:50:46 -07:00
2018-05-22 14:27:51 -04:00
2018-07-25 14:49:00 +01:00
2018-06-15 07:31:07 +09:00
2018-06-15 07:31:07 +09:00
2018-06-15 07:31:07 +09:00
2018-06-15 07:31:07 +09:00
2018-06-05 16:57:31 -07:00
2018-06-12 16:19:22 -07:00
2018-07-26 19:38:03 -07:00
2018-04-16 09:47:41 +02:00
2018-07-08 11:10:30 -07:00
2018-06-15 07:31:07 +09:00
2018-06-19 07:47:32 +09:00
2018-06-15 07:31:07 +09:00
2018-03-27 13:18:09 -04:00
2018-05-22 14:27:52 -04:00
2018-06-22 06:21:34 +09:00
2018-03-27 13:18:09 -04:00
2018-06-15 07:31:07 +09:00
2018-05-11 15:36:37 -04:00
2018-05-18 14:58:22 +02:00
2018-06-15 07:31:07 +09:00
2018-06-15 07:31:07 +09:00
2018-05-22 14:27:58 -04:00
2018-05-22 14:27:57 -04:00
2018-06-17 05:25:18 +09:00
2018-06-15 07:31:07 +09:00
2018-07-14 11:11:09 -07:00
2018-06-14 14:57:24 +02:00
2018-05-22 14:27:52 -04:00
2018-05-22 14:27:54 -04:00
2018-06-20 11:04:26 +02:00
2018-07-14 11:11:10 -07:00
2018-05-22 14:27:55 -04:00
2018-05-21 14:30:09 -04:00
2018-05-22 14:27:53 -04:00
2018-06-15 07:31:07 +09:00
2018-06-20 11:05:49 +02:00
2018-06-12 16:19:22 -07:00
2018-06-24 12:00:12 -07:00
2018-07-22 12:04:51 -07:00
2018-06-15 07:31:07 +09:00
2018-06-05 16:57:31 -07:00
2018-04-11 10:28:37 -07:00
2018-06-12 16:19:22 -07:00
2018-07-14 11:11:10 -07:00
2018-04-11 10:28:37 -07:00
2018-06-15 18:11:26 -03:00
2018-06-12 16:19:22 -07:00
2018-06-01 18:37:33 -07:00
2018-03-15 17:59:24 +01:00
2018-06-07 17:34:40 -07:00
2018-06-05 19:23:26 +02:00
2018-03-29 15:07:46 -04:00
2018-06-08 17:21:52 -07:00
2018-06-04 10:14:28 -07:00
2018-04-02 20:15:39 +02:00
2018-05-14 08:55:18 -06:00
2018-06-28 10:40:47 -07:00
2018-06-28 10:40:47 -07:00
2018-07-26 19:38:03 -07:00
2018-06-07 17:34:35 -07:00
2018-04-02 20:16:00 +02:00
2018-05-16 07:23:35 +02:00
2018-05-03 16:11:37 -06:00
2018-07-05 12:36:36 -07:00
2018-07-10 23:29:03 -04:00
2018-05-24 12:04:28 -05:00
2018-06-12 15:49:00 -07:00
2018-06-11 08:22:34 -07:00
2018-06-15 18:11:26 -03:00
2018-03-30 11:34:55 -07:00
2018-06-15 07:31:07 +09:00
2018-06-11 08:22:34 -07:00
2018-06-12 16:19:22 -07:00
2018-06-16 16:32:04 +09:00
2018-05-24 12:02:25 -05:00
2018-06-03 10:58:23 -07:00
2018-06-28 10:40:47 -07:00
2018-06-12 16:19:22 -07:00
2018-04-02 20:16:02 +02:00
2018-06-28 10:40:47 -07:00
2018-05-25 18:12:11 -07:00
2018-06-16 16:21:50 +09:00
2018-06-16 16:21:50 +09:00
2018-04-02 20:15:34 +02:00
2018-06-04 10:14:28 -07:00
2018-04-04 12:44:02 -07:00
2018-06-28 10:40:47 -07:00
2018-07-03 17:32:18 -07:00
2018-04-02 20:15:44 +02:00
2018-05-29 13:22:41 -04:00