android_kernel_motorola_sm6375/drivers
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Seunghun Han 4fa430a8bc ACPICA: fix acpi operand cache leak in dswstate.c
[ Upstream commit 156fd20a41e776bbf334bd5e45c4f78dfc90ce1c ]

ACPICA commit 987a3b5cf7175916e2a4b6ea5b8e70f830dfe732

I found an ACPI cache leak in ACPI early termination and boot continuing case.

When early termination occurs due to malicious ACPI table, Linux kernel
terminates ACPI function and continues to boot process. While kernel terminates
ACPI function, kmem_cache_destroy() reports Acpi-Operand cache leak.

Boot log of ACPI operand cache leak is as follows:
>[    0.585957] ACPI: Added _OSI(Module Device)
>[    0.587218] ACPI: Added _OSI(Processor Device)
>[    0.588530] ACPI: Added _OSI(3.0 _SCP Extensions)
>[    0.589790] ACPI: Added _OSI(Processor Aggregator Device)
>[    0.591534] ACPI Error: Illegal I/O port address/length above 64K: C806E00000004002/0x2 (20170303/hwvalid-155)
>[    0.594351] ACPI Exception: AE_LIMIT, Unable to initialize fixed events (20170303/evevent-88)
>[    0.597858] ACPI: Unable to start the ACPI Interpreter
>[    0.599162] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)
>[    0.601836] kmem_cache_destroy Acpi-Operand: Slab cache still has objects
>[    0.603556] CPU: 0 PID: 1 Comm: swapper/0 Not tainted 4.12.0-rc5 #26
>[    0.605159] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS virtual_box 12/01/2006
>[    0.609177] Call Trace:
>[    0.610063]  ? dump_stack+0x5c/0x81
>[    0.611118]  ? kmem_cache_destroy+0x1aa/0x1c0
>[    0.612632]  ? acpi_sleep_proc_init+0x27/0x27
>[    0.613906]  ? acpi_os_delete_cache+0xa/0x10
>[    0.617986]  ? acpi_ut_delete_caches+0x3f/0x7b
>[    0.619293]  ? acpi_terminate+0xa/0x14
>[    0.620394]  ? acpi_init+0x2af/0x34f
>[    0.621616]  ? __class_create+0x4c/0x80
>[    0.623412]  ? video_setup+0x7f/0x7f
>[    0.624585]  ? acpi_sleep_proc_init+0x27/0x27
>[    0.625861]  ? do_one_initcall+0x4e/0x1a0
>[    0.627513]  ? kernel_init_freeable+0x19e/0x21f
>[    0.628972]  ? rest_init+0x80/0x80
>[    0.630043]  ? kernel_init+0xa/0x100
>[    0.631084]  ? ret_from_fork+0x25/0x30
>[    0.633343] vgaarb: loaded
>[    0.635036] EDAC MC: Ver: 3.0.0
>[    0.638601] PCI: Probing PCI hardware
>[    0.639833] PCI host bridge to bus 0000:00
>[    0.641031] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
> ... Continue to boot and log is omitted ...

I analyzed this memory leak in detail and found acpi_ds_obj_stack_pop_and_
delete() function miscalculated the top of the stack. acpi_ds_obj_stack_push()
function uses walk_state->operand_index for start position of the top, but
acpi_ds_obj_stack_pop_and_delete() function considers index 0 for it.
Therefore, this causes acpi operand memory leak.

This cache leak causes a security threat because an old kernel (<= 4.9) shows
memory locations of kernel functions in stack dump. Some malicious users
could use this information to neutralize kernel ASLR.

I made a patch to fix ACPI operand cache leak.

Link: 987a3b5c
Signed-off-by: Seunghun Han <kkamagui@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/4999480.31r3eYUQgx@rjwysocki.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:52 +01:00
..
accessibility
acpi ACPICA: fix acpi operand cache leak in dswstate.c 2025-06-27 11:02:52 +01:00
amba
android binder: fix UAF caused by offsets overwrite 2024-09-12 11:03:55 +02:00
ata ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 2025-06-27 11:02:51 +01:00
atm
auxdisplay
base pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id() 2025-06-27 11:02:49 +01:00
bcma
block nbd: don't allow reconnect after disconnect 2025-03-13 12:42:52 +01:00
bluetooth Bluetooth: btrtl: Prevent potential NULL dereference 2025-05-02 07:39:19 +02:00
bus bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device 2025-06-27 11:02:51 +01:00
cdrom
char virtio_console: fix missing byte order handling for cols and rows 2025-05-02 07:39:26 +02:00
clk clk: check for disabled clock-provider in of_clk_get_hw_from_clkspec() 2025-05-02 07:39:28 +02:00
clocksource clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable() 2025-06-04 14:32:29 +02:00
connector
counter counter: stm32-lptimer-cnt: fix error handling when enabling 2025-04-10 14:29:39 +02:00
cpufreq cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() 2025-05-02 07:39:25 +02:00
cpuidle cpuidle: menu: Avoid discarding useful information 2025-06-04 14:32:32 +02:00
crypto crypto: marvell/cesa - Avoid empty transfer descriptor 2025-06-27 11:02:45 +01:00
dax
dca
devfreq
dio
dma dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when interrupted" 2025-06-04 14:32:29 +02:00
dma-buf udmabuf: fix a buf size overflow issue during udmabuf creation 2025-05-02 07:39:29 +02:00
edac EDAC/altera: Use correct write width with the INTTEST register 2025-06-27 11:02:51 +01:00
eisa
extcon
firewire
firmware firmware: psci: Fix refcount leak in psci_dt_init 2025-06-27 11:02:46 +01:00
fpga fpga: altera-cvp: Increase credit timeout 2025-06-04 14:32:32 +02:00
fsi
gnss
gpio gpio: zynq: Fix wakeup source leaks on device unbind 2025-05-02 07:39:17 +02:00
gpu drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang 2025-06-27 11:02:50 +01:00
greybus
hid HID: quirks: Add ADATA XPG alpha wireless mouse support 2025-06-04 14:32:37 +02:00
hsi HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition 2025-05-02 07:39:18 +02:00
hv Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio() 2025-04-10 14:29:35 +02:00
hwmon hwmon: (xgene-hwmon) use appropriate type for the latency value 2025-06-04 14:32:34 +02:00
hwspinlock
hwtracing coresight: catu: Fix number of pages while using 64k pages 2025-04-10 14:29:41 +02:00
i2c i2c: pxa: fix call balance of i2c->clk handling routines 2025-06-04 14:32:30 +02:00
i3c i3c: Add NULL pointer check in i3c_master_queue_ibi() 2025-05-02 07:39:15 +02:00
ide
idle
iio iio: adc: ad7606_spi: fix reg write value mask 2025-06-27 11:02:52 +01:00
infiniband RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h 2025-06-27 11:02:46 +01:00
input Input: ims-pcu - check record size in ims_pcu_flash_firmware() 2025-06-27 11:02:51 +01:00
interconnect
iommu iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid 2025-06-04 14:32:26 +02:00
ipack
irqchip irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() 2025-06-04 14:32:25 +02:00
isdn
leds leds: lp8860: Write full EEPROM, not only half of it 2025-03-13 12:43:06 +01:00
lightnvm
macintosh
mailbox mailbox: use error ret code of of_parse_phandle_with_args() 2025-06-04 14:32:30 +02:00
mcb mcb: fix a double free bug in chameleon_parse_gdd() 2025-05-02 07:39:26 +02:00
md dm-mirror: fix a tiny race condition 2025-06-27 11:02:52 +01:00
media media: v4l2-dev: fix error handling in __video_register_device() 2025-06-27 11:02:51 +01:00
memory
memstick memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove 2025-04-10 14:29:39 +02:00
message scsi: fusion: Remove unused variable 'rc' 2024-12-14 19:44:29 +01:00
mfd mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE 2025-06-27 11:02:48 +01:00
misc misc: pci_endpoint_test: Fix displaying 'irq_type' after 'request_irq' error 2025-05-02 07:39:25 +02:00
mmc mmc: sdhci: Disable SD card clock before changing parameters 2025-06-04 14:32:31 +02:00
mtd mtd: nand: sunxi: Add randomizer configuration before randomizer enable 2025-06-27 11:02:52 +01:00
mux
net net: ch9200: fix uninitialised access during mii_nway_restart 2025-06-27 11:02:52 +01:00
nfc nfc: pn533: Add poll mod list filling check 2024-09-04 13:15:04 +02:00
ntb ntb: reduce stack usage in idt_scan_mws 2025-05-02 07:39:28 +02:00
nubus
nvdimm libnvdimm/labels: Fix divide error in nd_label_data_init() 2025-06-04 14:32:30 +02:00
nvme nvmet-tcp: don't restore null sk_state_change 2025-06-04 14:32:35 +02:00
nvmem nvmem: core: improve range check for nvmem_cell_write() 2025-03-13 12:43:10 +01:00
of of: module: add buffer overflow check in of_modalias() 2025-06-04 14:32:25 +02:00
opp
oprofile
parisc
parport parport_pc: add support for ASIX AX99100 2025-03-13 12:43:19 +01:00
pci PCI: Fix lock symmetry in pci_slot_unlock() 2025-06-27 11:02:52 +01:00
pcmcia pcmcia: Use resource_size function on resource object 2024-09-12 11:03:52 +02:00
perf perf: arm_pmu: Don't disable counter in armpmu_add() 2025-05-02 07:39:09 +02:00
phy phy: core: don't require set_mode() callback for phy_get_mode() to work 2025-06-04 14:32:33 +02:00
pinctrl pinctrl: at91: Fix possible out-of-boundary access 2025-06-27 11:02:46 +01:00
platform platform/x86: thinkpad_acpi: Ignore battery threshold change event notification 2025-06-04 14:32:37 +02:00
pnp
power power: supply: max77693: Fix wrong conversion of charge input threshold value 2025-04-10 14:29:41 +02:00
powercap powercap: call put_device() on an error path in powercap_register_control_type() 2025-04-10 14:29:36 +02:00
pps pps: Fix a use-after-free 2025-03-13 12:43:19 +01:00
ps3
ptp ptp: Ensure info->enable callback is always set 2025-03-13 12:43:11 +01:00
pwm pwm: mediatek: always use bus clock for PWM on MT7622 2025-05-02 07:39:18 +02:00
rapidio rapidio: fix an API misues when rio_add_net() fails 2025-03-13 12:43:28 +01:00
ras
regulator regulator: max14577: Add error check for max14577_read_reg() 2025-06-27 11:02:52 +01:00
remoteproc
reset reset: berlin: fix OF node leak in probe() error path 2024-11-08 16:20:28 +01:00
rpmsg rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send() 2025-06-27 11:02:48 +01:00
rtc rtc: Fix offset calculation for .start_secs < 0 2025-06-27 11:02:48 +01:00
s390 s390/cio: Fix CHPID "configure" attribute caching 2025-04-10 14:29:36 +02:00
sbus
scsi scsi: iscsi: Fix incorrect error path labels for flashnode operations 2025-06-27 11:02:49 +01:00
sfi
sh sh: clk: Fix clk_enable() to return 0 on NULL clk 2025-01-09 13:23:29 +01:00
siox
slimbus slimbus: messaging: Free transaction ID in delayed interrupt scenario 2025-03-13 12:43:33 +01:00
soc soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() 2025-06-27 11:02:48 +01:00
soundwire soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps" 2024-11-08 16:20:25 +01:00
spi spi: sh-msiof: Fix maximum DMA transfer size 2025-06-27 11:02:45 +01:00
spmi
ssb
staging staging: iio: ad5933: Correct settling cycles encoding per datasheet 2025-06-27 11:02:52 +01:00
target scsi: target: iscsi: Fix timeout on deleted connection 2025-06-04 14:32:29 +02:00
tc
tee tee: optee: Fix supplicant wait loop 2025-03-13 12:43:23 +01:00
thermal thermal/drivers/rockchip: Add missing rk3328 mapping entry 2025-05-02 07:39:16 +02:00
thunderbolt thunderbolt: Do not double dequeue a configuration request 2025-06-27 11:02:44 +01:00
tty vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl() 2025-06-27 11:02:48 +01:00
uio uio_hv_generic: Use correct size for interrupt and monitor pages 2025-06-27 11:02:52 +01:00
usb usb: Flush altsetting 0 endpoints before reinitializating them after reset. 2025-06-27 11:02:50 +01:00
vfio vfio/pci: Enable iowrite64 and ioread64 for vfio pci 2025-03-13 12:43:13 +01:00
vhost
video vgacon: Add check for vc_origin address range in vgacon_scroll() 2025-06-27 11:02:51 +01:00
virt
virtio
visorbus
vlynq
vme
w1
watchdog watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart() 2024-12-14 19:44:44 +01:00
xen xen/swiotlb: relax alignment requirements 2025-06-04 14:32:37 +02:00
zorro
Kconfig
Makefile