All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] uprobes: fix kernel info leak via "[uprobes]" vma
@ 2024-09-26 16:29 Oleg Nesterov
  2024-09-29 13:39 ` Masami Hiramatsu
  2024-09-29 16:20 ` [PATCH v2] " Oleg Nesterov
  0 siblings, 2 replies; 6+ messages in thread
From: Oleg Nesterov @ 2024-09-26 16:29 UTC (permalink / raw)
  To: Masami Hiramatsu, Peter Zijlstra
  Cc: Catalin Marinas, Liao, Chang, Will Deacon, linux-kernel

xol_add_vma() maps the uninitialized page allocated by __create_xol_area()
into userspace. On some architectures (x86) this memory is readable even
without VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ.

Reported-by: Will Deacon <will@kernel.org>
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
---
 kernel/events/uprobes.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/events/uprobes.c b/kernel/events/uprobes.c
index 2ec796e2f055..4b52cb2ae6d6 100644
--- a/kernel/events/uprobes.c
+++ b/kernel/events/uprobes.c
@@ -1545,7 +1545,7 @@ static struct xol_area *__create_xol_area(unsigned long vaddr)
 	if (!area->bitmap)
 		goto free_area;
 
-	area->page = alloc_page(GFP_HIGHUSER);
+	area->page = alloc_page(GFP_HIGHUSER | __GFP_ZERO);
 	if (!area->page)
 		goto free_bitmap;
 
-- 
2.25.1.362.g51ebf55



^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-09-29 16:21 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-09-26 16:29 [PATCH] uprobes: fix kernel info leak via "[uprobes]" vma Oleg Nesterov
2024-09-29 13:39 ` Masami Hiramatsu
2024-09-29 14:50   ` Oleg Nesterov
2024-09-29 15:39     ` Masami Hiramatsu
2024-09-29 15:56       ` Oleg Nesterov
2024-09-29 16:20 ` [PATCH v2] " Oleg Nesterov

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.