From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Lin Feng <linf@wangsu.com>, Alexey Dobriyan <adobriyan@gmail.com>,
"Eric W. Biederman" <ebiederm@xmission.com>,
Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>,
Sasha Levin <sashal@kernel.org>
Subject: [PATCH AUTOSEL 5.11 48/52] sysctl.c: fix underflow value setting risk in vm_table
Date: Tue, 2 Mar 2021 06:55:29 -0500 [thread overview]
Message-ID: <20210302115534.61800-48-sashal@kernel.org> (raw)
In-Reply-To: <20210302115534.61800-1-sashal@kernel.org>
From: Lin Feng <linf@wangsu.com>
[ Upstream commit 3b3376f222e3ab58367d9dd405cafd09d5e37b7c ]
Apart from subsystem specific .proc_handler handler, all ctl_tables with
extra1 and extra2 members set should use proc_dointvec_minmax instead of
proc_dointvec, or the limit set in extra* never work and potentially echo
underflow values(negative numbers) is likely make system unstable.
Especially vfs_cache_pressure and zone_reclaim_mode, -1 is apparently not
a valid value, but we can set to them. And then kernel may crash.
# echo -1 > /proc/sys/vm/vfs_cache_pressure
Link: https://lkml.kernel.org/r/20201223105535.2875-1-linf@wangsu.com
Signed-off-by: Lin Feng <linf@wangsu.com>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sysctl.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/kernel/sysctl.c b/kernel/sysctl.c
index c9fbdd848138..62fbd09b5dc1 100644
--- a/kernel/sysctl.c
+++ b/kernel/sysctl.c
@@ -2962,7 +2962,7 @@ static struct ctl_table vm_table[] = {
.data = &block_dump,
.maxlen = sizeof(block_dump),
.mode = 0644,
- .proc_handler = proc_dointvec,
+ .proc_handler = proc_dointvec_minmax,
.extra1 = SYSCTL_ZERO,
},
{
@@ -2970,7 +2970,7 @@ static struct ctl_table vm_table[] = {
.data = &sysctl_vfs_cache_pressure,
.maxlen = sizeof(sysctl_vfs_cache_pressure),
.mode = 0644,
- .proc_handler = proc_dointvec,
+ .proc_handler = proc_dointvec_minmax,
.extra1 = SYSCTL_ZERO,
},
#if defined(HAVE_ARCH_PICK_MMAP_LAYOUT) || \
@@ -2980,7 +2980,7 @@ static struct ctl_table vm_table[] = {
.data = &sysctl_legacy_va_layout,
.maxlen = sizeof(sysctl_legacy_va_layout),
.mode = 0644,
- .proc_handler = proc_dointvec,
+ .proc_handler = proc_dointvec_minmax,
.extra1 = SYSCTL_ZERO,
},
#endif
@@ -2990,7 +2990,7 @@ static struct ctl_table vm_table[] = {
.data = &node_reclaim_mode,
.maxlen = sizeof(node_reclaim_mode),
.mode = 0644,
- .proc_handler = proc_dointvec,
+ .proc_handler = proc_dointvec_minmax,
.extra1 = SYSCTL_ZERO,
},
{
--
2.30.1
next prev parent reply other threads:[~2021-03-03 0:46 UTC|newest]
Thread overview: 56+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-03-02 11:54 [PATCH AUTOSEL 5.11 01/52] i2c: rcar: faster irq code to minimize HW race condition Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 02/52] i2c: rcar: optimize cacheline " Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 03/52] scsi: ufs: Add a quirk to permit overriding UniPro defaults Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 04/52] scsi: pm80xx: Fix missing tag_free in NVMD DATA req Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 05/52] scsi: ufs: WB is only available on LUN #0 to #7 Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 06/52] scsi: ufs: Introduce a quirk to allow only page-aligned sg entries Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 07/52] scsi: ufs: Protect some contexts from unexpected clock scaling Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 08/52] udf: fix silent AED tagLocation corruption Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 09/52] iommu/vt-d: Clear PRQ overflow only when PRQ is empty Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 10/52] mmc: mxs-mmc: Fix a resource leak in an error handling path in 'mxs_mmc_probe()' Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 11/52] mmc: sdhci-of-dwcmshc: set SDHCI_QUIRK2_PRESET_VALUE_BROKEN Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 12/52] mmc: mediatek: fix race condition between msdc_request_timeout and irq Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 13/52] mmc: sdhci-iproc: Add ACPI bindings for the RPi Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 14/52] platform/x86: amd-pmc: put device on error paths Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 15/52] Platform: OLPC: Fix probe error handling Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 16/52] powerpc/pci: Add ppc_md.discover_phbs() Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 17/52] HID: i2c-hid: Add I2C_HID_QUIRK_NO_IRQ_AFTER_RESET for ITE8568 EC on Voyo Winpad A15 Sasha Levin
2021-03-02 11:54 ` [PATCH AUTOSEL 5.11 18/52] spi: stm32: make spurious and overrun interrupts visible Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 19/52] powerpc: improve handling of unrecoverable system reset Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 20/52] powerpc/perf: Record counter overflow always if SAMPLE_IP is unset Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 21/52] kunit: tool: fix unit test cleanup handling Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 22/52] HID: logitech-dj: add support for the new lightspeed connection iteration Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 23/52] HID: ite: Enable QUIRK_TOUCHPAD_ON_OFF_REPORT on Acer Aspire Switch 10E Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 24/52] powerpc/64: Fix stack trace not displaying final frame Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 25/52] iommu/amd: Fix performance counter initialization Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 26/52] clk: qcom: gdsc: Implement NO_RET_PERIPH flag Sasha Levin
2021-03-02 23:02 ` Stephen Boyd
2021-03-04 21:30 ` Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 27/52] sparc32: Limit memblock allocation to low memory Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 28/52] sparc64: Use arch_validate_flags() to validate ADI flag Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 29/52] ACPICA: Fix race in generic_serial_bus (I2C) and GPIO op_region parameter handling Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 30/52] Input: applespi - don't wait for responses to commands indefinitely Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 31/52] x86, build: use objtool mcount Sasha Levin
2021-03-02 18:42 ` Kees Cook
2021-03-12 22:10 ` Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 32/52] PCI: xgene-msi: Fix race in installing chained irq handler Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 33/52] misc: eeprom_93xx46: Add quirk to support Microchip 93LC46B eeprom Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 34/52] PCI: mediatek: Add missing of_node_put() to fix reference leak Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 35/52] drivers/base: build kunit tests without structleak plugin Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 36/52] drm/msm/a5xx: Remove overwriting A5XX_PC_DBG_ECO_CNTL register Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 37/52] PCI/LINK: Remove bandwidth notification Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 38/52] ext4: don't try to processed freed blocks until mballoc is initialized Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 39/52] PCI: cadence: Retrain Link to work around Gen2 training defect Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 40/52] kbuild: clamp SUBLEVEL to 255 Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 41/52] PCI: Fix pci_register_io_range() memory leak Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 42/52] i40e: Fix memory leak in i40e_probe Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 43/52] PCI/ERR: Retain status from error notification Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 44/52] kasan: fix memory corruption in kasan_bitops_tags test Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 45/52] riscv: Get rid of MAX_EARLY_MAPPING_SIZE Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 46/52] s390/smp: __smp_rescan_cpus() - move cpumask away from stack Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 47/52] drivers/base/memory: don't store phys_device in memory blocks Sasha Levin
2021-03-02 11:55 ` Sasha Levin [this message]
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 49/52] scsi: libiscsi: Fix iscsi_prep_scsi_cmd_pdu() error handling Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 50/52] nbd: handle device refs for DESTROY_ON_DISCONNECT properly Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 51/52] scsi: target: core: Add cmd length set before cmd complete Sasha Levin
2021-03-02 11:55 ` [PATCH AUTOSEL 5.11 52/52] scsi: target: core: Prevent underflow for service actions Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210302115534.61800-48-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=adobriyan@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=ebiederm@xmission.com \
--cc=linf@wangsu.com \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox