Eric Dumazet
706a813e22
sctp: do not leak kernel memory to user space
...
[ Upstream commit 6780db244d6b1537d139dea0ec8aad10cf9e4adb ]
syzbot produced a nice report [1]
Issue here is that a recvmmsg() managed to leak 8 bytes of kernel memory
to user space, because sin_zero (padding field) was not properly cleared.
[1]
BUG: KMSAN: uninit-value in copy_to_user include/linux/uaccess.h:184 [inline]
BUG: KMSAN: uninit-value in move_addr_to_user+0x32e/0x530 net/socket.c:227
CPU: 1 PID: 3586 Comm: syzkaller481044 Not tainted 4.16.0+ #82
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x185/0x1d0 lib/dump_stack.c:53
kmsan_report+0x142/0x240 mm/kmsan/kmsan.c:1067
kmsan_internal_check_memory+0x164/0x1d0 mm/kmsan/kmsan.c:1176
kmsan_copy_to_user+0x69/0x160 mm/kmsan/kmsan.c:1199
copy_to_user include/linux/uaccess.h:184 [inline]
move_addr_to_user+0x32e/0x530 net/socket.c:227
___sys_recvmsg+0x4e2/0x810 net/socket.c:2211
__sys_recvmmsg+0x54e/0xdb0 net/socket.c:2313
SYSC_recvmmsg+0x29b/0x3e0 net/socket.c:2394
SyS_recvmmsg+0x76/0xa0 net/socket.c:2378
do_syscall_64+0x309/0x430 arch/x86/entry/common.c:287
entry_SYSCALL_64_after_hwframe+0x3d/0xa2
RIP: 0033:0x4401c9
RSP: 002b:00007ffc56f73098 EFLAGS: 00000217 ORIG_RAX: 000000000000012b
RAX: ffffffffffffffda RBX: 00000000004002c8 RCX: 00000000004401c9
RDX: 0000000000000001 RSI: 0000000020003ac0 RDI: 0000000000000003
RBP: 00000000006ca018 R08: 0000000020003bc0 R09: 0000000000000010
R10: 0000000000000000 R11: 0000000000000217 R12: 0000000000401af0
R13: 0000000000401b80 R14: 0000000000000000 R15: 0000000000000000
Local variable description: ----addr@___sys_recvmsg
Variable was created at:
___sys_recvmsg+0xd5/0x810 net/socket.c:2172
__sys_recvmmsg+0x54e/0xdb0 net/socket.c:2313
Bytes 8-15 of 16 are uninitialized
==================================================================
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 3586 Comm: syzkaller481044 Tainted: G B 4.16.0+ #82
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x185/0x1d0 lib/dump_stack.c:53
panic+0x39d/0x940 kernel/panic.c:183
kmsan_report+0x238/0x240 mm/kmsan/kmsan.c:1083
kmsan_internal_check_memory+0x164/0x1d0 mm/kmsan/kmsan.c:1176
kmsan_copy_to_user+0x69/0x160 mm/kmsan/kmsan.c:1199
copy_to_user include/linux/uaccess.h:184 [inline]
move_addr_to_user+0x32e/0x530 net/socket.c:227
___sys_recvmsg+0x4e2/0x810 net/socket.c:2211
__sys_recvmmsg+0x54e/0xdb0 net/socket.c:2313
SYSC_recvmmsg+0x29b/0x3e0 net/socket.c:2394
SyS_recvmmsg+0x76/0xa0 net/socket.c:2378
do_syscall_64+0x309/0x430 arch/x86/entry/common.c:287
entry_SYSCALL_64_after_hwframe+0x3d/0xa2
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Vlad Yasevich <vyasevich@gmail.com>
Cc: Neil Horman <nhorman@tuxdriver.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2018-04-13 19:50:25 +02:00
..
2015-10-21 00:49:25 +02:00
2017-11-30 08:37:25 +00:00
2018-03-22 09:23:21 +01:00
2015-09-17 22:13:32 -07:00
2017-02-04 09:45:09 +01:00
2018-03-22 09:23:21 +01:00
2018-04-13 19:50:21 +02:00
2018-04-08 11:51:59 +02:00
2017-07-05 14:37:14 +02:00
2018-01-31 12:06:08 +01:00
2018-04-13 19:50:10 +02:00
2018-04-13 19:50:24 +02:00
2015-10-09 07:52:27 -07:00
2018-03-31 18:12:33 +02:00
2018-02-25 11:03:38 +01:00
2017-10-27 10:23:18 +02:00
2017-11-15 17:13:11 +01:00
2017-02-18 16:39:27 +01:00
2015-11-23 14:56:15 -05:00
2018-04-13 19:50:10 +02:00
2018-04-13 19:50:24 +02:00
2018-04-13 19:50:24 +02:00
2017-05-25 14:30:13 +02:00
2017-08-30 10:19:21 +02:00
2018-03-31 18:12:33 +02:00
2018-04-13 19:50:01 +02:00
2018-04-13 19:50:12 +02:00
2015-10-07 04:27:43 -07:00
2018-04-13 19:50:12 +02:00
2018-04-13 19:50:01 +02:00
2015-10-21 00:49:24 +02:00
2018-03-11 16:19:47 +01:00
2018-04-13 19:50:10 +02:00
2016-08-20 18:09:22 +02:00
2018-04-13 19:50:24 +02:00
2017-11-30 08:37:23 +00:00
2018-03-24 10:58:43 +01:00
2017-12-16 10:33:56 +01:00
2016-01-31 11:29:00 -08:00
2018-04-13 19:50:13 +02:00
2016-03-03 15:07:26 -08:00
2018-04-13 19:50:23 +02:00
2018-04-13 19:50:25 +02:00
2018-04-13 19:50:25 +02:00
2018-04-13 19:50:15 +02:00
2016-06-24 10:18:16 -07:00
2017-12-16 10:33:56 +01:00
2017-11-18 11:11:06 +01:00
2017-11-30 08:37:19 +00:00
2015-08-09 22:43:52 -07:00
2018-02-25 11:03:53 +01:00
2018-04-13 19:50:07 +02:00
2018-04-13 19:50:08 +02:00
2017-10-08 10:14:18 +02:00
2018-02-25 11:03:37 +01:00
2015-09-29 20:40:32 -07:00
2018-02-03 17:04:24 +01:00
2016-09-15 08:27:50 +02:00