Linux kernel -stable discussions
 help / color / mirror / Atom feed
* Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable
@ 2017-11-27  8:03 Eric Biggers
  2017-11-27  8:34 ` Greg Kroah-Hartman
  2017-11-27  9:09 ` Vlastimil Babka
  0 siblings, 2 replies; 3+ messages in thread
From: Eric Biggers @ 2017-11-27  8:03 UTC (permalink / raw)
  To: stable, Greg Kroah-Hartman
  Cc: Vlastimil Babka, Dmitry Vyukov, Kirill A. Shutemov,
	Andrea Arcangeli, Laurent Dufour

Commit cb0631fd3cf9 ("x86/mm: fix use-after-free of vma during userfaultfd
fault") went into mainline without Cc: stable.  It appears to be a
use-after-free reachable by unprivileged users -- at least with
CONFIG_USERFAULTFD=y.  Can it please be applied to 4.9-stable?

Eric

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable
  2017-11-27  8:03 Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable Eric Biggers
@ 2017-11-27  8:34 ` Greg Kroah-Hartman
  2017-11-27  9:09 ` Vlastimil Babka
  1 sibling, 0 replies; 3+ messages in thread
From: Greg Kroah-Hartman @ 2017-11-27  8:34 UTC (permalink / raw)
  To: Eric Biggers
  Cc: stable, Vlastimil Babka, Dmitry Vyukov, Kirill A. Shutemov,
	Andrea Arcangeli, Laurent Dufour

On Mon, Nov 27, 2017 at 12:03:43AM -0800, Eric Biggers wrote:
> Commit cb0631fd3cf9 ("x86/mm: fix use-after-free of vma during userfaultfd
> fault") went into mainline without Cc: stable.  It appears to be a
> use-after-free reachable by unprivileged users -- at least with
> CONFIG_USERFAULTFD=y.  Can it please be applied to 4.9-stable?

Now queued up, thanks,

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable
  2017-11-27  8:03 Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable Eric Biggers
  2017-11-27  8:34 ` Greg Kroah-Hartman
@ 2017-11-27  9:09 ` Vlastimil Babka
  1 sibling, 0 replies; 3+ messages in thread
From: Vlastimil Babka @ 2017-11-27  9:09 UTC (permalink / raw)
  To: Eric Biggers, stable, Greg Kroah-Hartman
  Cc: Dmitry Vyukov, Kirill A. Shutemov, Andrea Arcangeli,
	Laurent Dufour

On 11/27/2017 09:03 AM, Eric Biggers wrote:
> Commit cb0631fd3cf9 ("x86/mm: fix use-after-free of vma during userfaultfd
> fault") went into mainline without Cc: stable.  It appears to be a

It was a mainline 4.14-rcX regression fix so I didn't CC stable. I
didn't notice that the commit a3c4fb7c9c2ebfd50b8c60f6c069932bb319bc37
that it Fixes did have CC: stable, so I guess my fix should have CC:
stable too. Probably the stable scripts should have picked that anyway,
except I also screwed copy/paste on the Fixes tag, omitting the first
characted of SHA :( (Fixes: 3c4fb7c9c2e ("x86/mm: ...."))

Thanks for noticing!

> use-after-free reachable by unprivileged users -- at least with
> CONFIG_USERFAULTFD=y.  Can it please be applied to 4.9-stable?
> 
> Eric
> 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2017-11-27  9:11 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-11-27  8:03 Apply "x86/mm: fix use-after-free of vma during userfaultfd fault" to 4.9-stable Eric Biggers
2017-11-27  8:34 ` Greg Kroah-Hartman
2017-11-27  9:09 ` Vlastimil Babka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox