All of lore.kernel.org
 help / color / mirror / Atom feed
From: Michal Hocko <mhocko@suse.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: cve@kernel.org, linux-kernel@vger.kernel.org
Subject: Re: CVE-2021-47090: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
Date: Wed, 6 Mar 2024 09:06:42 +0100	[thread overview]
Message-ID: <ZegkEqtGcC1p_7Xb@tiehlicka> (raw)
In-Reply-To: <2024030541-unhappily-staff-8662@gregkh>

On Tue 05-03-24 22:20:17, Greg KH wrote:
> On Tue, Mar 05, 2024 at 07:45:04PM +0100, Michal Hocko wrote:
> > On Mon 04-03-24 19:11:17, Greg KH wrote:
> > > Description
> > > ===========
> > > 
> > > In the Linux kernel, the following vulnerability has been resolved:
> > > 
> > > mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
> > 
> > I would like to dispute this CVE. The interface is behind CAP_SYSADMIN
> > and allowing access to this to any untrusted party is risking serious
> > troubles. This is a testing only feature.
> 
> This fixes a weakness in the kernel, one that is allowed to crash it,
> why isn't that a good thing to have a CVE entry for?  Are we saying that
> all VM_BUG_ON_PAGE() instances should not be accounted for?  That's not
> what the config option for CONFIG_DEBUG_VM says, it just says it will
> affect performance.

I wouldn't personaly recommend anybody using CONFIG_DEBUG_VM=y in
production. But I am not questioning if somebody does that. This is
not really what I am objecting to. Hwpoisoning or soft offlining is not
aimed for other than testing purposes. Things can go wrong during
these oprations.

If you insist this still qualifies as a vulnaribility/weakness fix then
I would propose a new category pig-with-a-lipstick-CVE.

> Also /sys/devices/system/memory/soft_offline_page doesn't say "can crash
> the system", so it should work properly, even if an admin uses it, it
> shouldn't shut the box down.

I agree that Documentation/ABI/testing/sysfs-memory-page-offline would
benefit from an update. Documentation/admin-guide/mm/memory-hotplug.rst
is explicit about this being a testing feature.
-- 
Michal Hocko
SUSE Labs

  reply	other threads:[~2024-03-06  8:06 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-03-04 18:11 CVE-2021-47090: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Greg Kroah-Hartman
2024-03-05 18:45 ` Michal Hocko
2024-03-05 22:20   ` Greg Kroah-Hartman
2024-03-06  8:06     ` Michal Hocko [this message]
2024-03-06  8:40       ` Greg Kroah-Hartman
2024-03-06  8:41       ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZegkEqtGcC1p_7Xb@tiehlicka \
    --to=mhocko@suse.com \
    --cc=cve@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.