public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] avr32: fix integer overflow in ELF_ET_DYN_BASE
@ 2015-03-24 15:31 Andrey Ryabinin
  2015-03-24 15:31 ` [PATCH] cris: " Andrey Ryabinin
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Andrey Ryabinin @ 2015-03-24 15:31 UTC (permalink / raw)
  To: Haavard Skinnemoen, Hans-Christian Egtvedt, linux-kernel
  Cc: Kees Cook, Yury Gribov, Andrey Ryabinin

Almost all arches define ELF_ET_DYN_BASE as 2/3 of TASK_SIZE.
Though it seems that some architectures do this in a wrong way.
The problem is that 2*TASK_SIZE may overflow 32-bits so
the real ELF_ET_DYN_BASE becomes wrong.
Fix this overflow by dividing TASK_SIZE prior to multiplying:
	 (TASK_SIZE / 3 * 2)

Signed-off-by: Andrey Ryabinin <a.ryabinin@samsung.com>
---
 arch/avr32/include/asm/elf.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/avr32/include/asm/elf.h b/arch/avr32/include/asm/elf.h
index d232888..0388ece 100644
--- a/arch/avr32/include/asm/elf.h
+++ b/arch/avr32/include/asm/elf.h
@@ -84,7 +84,7 @@ typedef struct user_fpu_struct elf_fpregset_t;
    the loader.  We need to make sure that it is out of the way of the program
    that it will "exec", and that there is sufficient room for the brk.  */
 
-#define ELF_ET_DYN_BASE         (2 * TASK_SIZE / 3)
+#define ELF_ET_DYN_BASE         (TASK_SIZE / 3 * 2)
 
 
 /* This yields a mask that user programs can use to figure out what
-- 
2.3.3


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2015-03-25 10:37 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-03-24 15:31 [PATCH] avr32: fix integer overflow in ELF_ET_DYN_BASE Andrey Ryabinin
2015-03-24 15:31 ` [PATCH] cris: " Andrey Ryabinin
2015-03-25 10:37   ` Jesper Nilsson
2015-03-24 15:31 ` [PATCH] x86, UML: " Andrey Ryabinin
2015-03-25  6:29 ` [PATCH] avr32: " Hans-Christian Egtvedt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox