From: David Mosberger <davidm@napali.hpl.hp.com>
To: linux-ia64@vger.kernel.org
Subject: Re: [PATCH] check user access ok writing /proc/irq/<pid>/smp_affinity
Date: Tue, 25 Nov 2003 07:11:58 +0000 [thread overview]
Message-ID: <marc-linux-ia64-106974433828664@msgid-missing> (raw)
In-Reply-To: <marc-linux-ia64-106973370622421@msgid-missing>
>>>>> On Mon, 24 Nov 2003 20:15:47 -0800, Paul Jackson <pj@sgi.com> said:
Paul> David,
Paul> Could you kindly apply the following patch?
Paul> In arch/ia64/kernel/irq.c:irq_affinity_write_proc() there
Paul> is an unchecked user access that examines writes to files
Paul> /proc/irq/<pid>/smp_affinity for a leading character 'R',
Paul> in order to trigger some interrupt redirect feature.
Paul> You can oops the kernel easily, by issuing a write() system
Paul> call to these files with a bogus address.
Paul> Here's a patch against test10 to fix it:
I see the problem, but the patch is incomplete: even after an
access_ok()-check, you'll need to use __get_user() to access the
buffer. Otherwise, the kernel will panic when accessing an unmapped
user-space address. Can you update the patch and re-test?
Thanks,
--david
prev parent reply other threads:[~2003-11-25 7:11 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-11-25 4:15 [PATCH] check user access ok writing /proc/irq/<pid>/smp_affinity Paul Jackson
2003-11-25 7:11 ` David Mosberger [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=marc-linux-ia64-106974433828664@msgid-missing \
--to=davidm@napali.hpl.hp.com \
--cc=linux-ia64@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox