Linux Device Mapper development
 help / color / mirror / Atom feed
From: Milan Broz <gmazyland@gmail.com>
To: Mikulas Patocka <mpatocka@redhat.com>,
	"Alasdair G. Kergon" <agk@redhat.com>,
	Mike Snitzer <msnitzer@redhat.com>,
	Milan Broz <gmazyland@gmail.com>,
	kkolasa@winsoft.pl
Cc: dm-devel@redhat.com
Subject: Re: [PATCH] dm-crypt: Fix access beyond the end of allocated space
Date: Thu, 28 Aug 2014 19:59:57 +0200	[thread overview]
Message-ID: <53FF6E1D.10308@gmail.com> (raw)
In-Reply-To: <alpine.LRH.2.02.1408281108120.31317@file01.intranet.prod.int.rdu2.redhat.com>

On 08/28/2014 05:09 PM, Mikulas Patocka wrote:
> dm-crypt has a bug that it accesses memory beyond allocated space.
> 
> To minimize allocation overhead, dm-crypt puts several structures into one
> block allocated with kmalloc. The block holds struct ablkcipher_request,
> cipher-specific scratch pad (crypto_ablkcipher_reqsize(any_tfm(cc))),
> struct dm_crypt_request and initialization vector.
> 
> The variable dmreq_start is set to offset of struct dm_crypt_request
> within this memory block. dm-crypt allocates block with this size:
> cc->dmreq_start + sizeof(struct dm_crypt_request) + cc->iv_size.
> 
> When accessing the initialization vector, dm-crypt uses the function
> iv_of_dmreq, which performs this calculation: ALIGN((unsigned long)(dmreq
> + 1), crypto_ablkcipher_alignmask(any_tfm(cc)) + 1).
> 
> dm-crypt allocated "cc->iv_size" bytes beyond the end of dm_crypt_request
> structure. However, when dm-crypt accesses the initialization vector, it
> takes a pointer to the end of dm_crypt_request, aligns it, and then uses
> it as the initialization vector.
> 
> If the end of dm_crypt_request is not aligned on
> crypto_ablkcipher_alignmask(any_tfm(cc)), the alignment causes
> initialization vector to point beyond the allocated space. This bug is
> very old (it dates back to commit 3a7f6c990ad04e6f576a159876c602d14d6f7fef
> in 2.6.25). However, the bug was masked by the fact that kmalloc rounds up
> the size to the next power of two. Recent change in dm-crypt that puts
> this structure to per-bio data (298a9fa08a1577211d42a75e8fc073baef61e0d9)
> made this bug show up, because there is no longer any padding beyond the
> end of iv_size.
> 
> This patch fixes the bug by calculating the variable iv_size_padding and
> adding it to the allocated size.
> 
> The patch also corrects alignment of dm_crypt_request. struct
> dm_crypt_request is specific to dm-crypt (it isn't used by the crypto
> subsystem at all), so it is aligned on __alignof__(struct
> dm_crypt_request).
> 
> The patch also aligns per_bio_data_size on ARCH_KMALLOC_MINALIGN, so that
> it is aligned as if the block was allocated with kmalloc.
> 
> Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>

Thanks for fixing this!

I tried all reproducers I have and no problems here with your patch.
(Except another unrelated oops in scsi_debug :-)

Tested-by: Milan Broz <gmazyland@gmail.com>

Milan

  reply	other threads:[~2014-08-28 17:59 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-08-28 15:09 [PATCH] dm-crypt: Fix access beyond the end of allocated space Mikulas Patocka
2014-08-28 17:59 ` Milan Broz [this message]
2014-08-28 18:40   ` Mike Snitzer
2014-08-28 19:28   ` [PATCH] " Krzysztof Kolasa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53FF6E1D.10308@gmail.com \
    --to=gmazyland@gmail.com \
    --cc=agk@redhat.com \
    --cc=dm-devel@redhat.com \
    --cc=kkolasa@winsoft.pl \
    --cc=mpatocka@redhat.com \
    --cc=msnitzer@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox