Jann Horn
c8157f67b0
timers: Prevent union confusion from unexpected restart_syscall()
...
[ Upstream commit 9f76d59173d9d146e96c66886b671c1915a5c5e5 ]
The nanosleep syscalls use the restart_block mechanism, with a quirk:
The `type` and `rmtp`/`compat_rmtp` fields are set up unconditionally on
syscall entry, while the rest of the restart_block is only set up in the
unlikely case that the syscall is actually interrupted by a signal (or
pseudo-signal) that doesn't have a signal handler.
If the restart_block was set up by a previous syscall (futex(...,
FUTEX_WAIT, ...) or poll()) and hasn't been invalidated somehow since then,
this will clobber some of the union fields used by futex_wait_restart() and
do_restart_poll().
If userspace afterwards wrongly calls the restart_syscall syscall,
futex_wait_restart()/do_restart_poll() will read struct fields that have
been clobbered.
This doesn't actually lead to anything particularly interesting because
none of the union fields contain trusted kernel data, and
futex(..., FUTEX_WAIT, ...) and poll() aren't syscalls where it makes much
sense to apply seccomp filters to their arguments.
So the current consequences are just of the "if userspace does bad stuff,
it can damage itself, and that's not a problem" flavor.
But still, it seems like a hazard for future developers, so invalidate the
restart_block when partly setting it up in the nanosleep syscalls.
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Link: https://lore.kernel.org/r/20230105134403.754986-1-jannh@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-03-11 16:43:54 +01:00
..
bpf
bpf: add missing header file include
2023-02-25 11:53:27 +01:00
cgroup
memcg: fix possible use-after-free in memcg_write_event_control()
2022-12-14 11:30:43 +01:00
configs
debug
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-03-11 16:43:42 +01:00
dma
dma-debug: make things less spammy under memory pressure
2022-06-22 14:11:19 +02:00
events
perf: Fix possible memleak in pmu_dev_alloc()
2023-01-18 11:40:53 +01:00
gcov
gcov: add support for checksum field
2023-01-18 11:41:42 +01:00
irq
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-03-11 16:43:42 +01:00
livepatch
livepatch: fix race between fork and KLP transition
2022-10-26 13:22:18 +02:00
locking
locking/lockdep: Avoid RCU-induced noinstr fail
2021-11-17 09:48:28 +01:00
power
PM: hibernate: Fix mistake in kerneldoc comment
2023-01-18 11:40:53 +01:00
printk
printk: fix return value of printk.devkmsg __setup handler
2022-04-15 14:18:08 +02:00
rcu
rcu: Suppress smp_processor_id() complaint in synchronize_rcu_expedited_wait()
2023-03-11 16:43:54 +01:00
sched
sched/rt: pick_next_rt_entity(): check list_entry
2023-03-11 16:43:35 +01:00
time
timers: Prevent union confusion from unexpected restart_syscall()
2023-03-11 16:43:54 +01:00
trace
tracing: Fix poll() and select() do not work on per_cpu trace_pipe and trace_pipe_raw
2023-02-22 12:50:30 +01:00
.gitignore
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
acct.c
acct: fix potential integer overflow in encode_comp_t()
2023-01-18 11:41:34 +01:00
async.c
Revert "module, async: async_synchronize_full() on module init iff async is used"
2022-02-23 11:59:56 +01:00
audit.c
audit: improve audit queue handling when "audit=1" on cmdline
2022-02-08 18:24:26 +01:00
audit.h
audit: log AUDIT_TIME_* records only from rules
2022-04-15 14:18:04 +02:00
audit_fsnotify.c
audit: fix potential double free on error path from fsnotify_add_inode_mark
2022-09-05 10:27:38 +02:00
audit_tree.c
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
2021-09-03 10:08:16 +02:00
audit_watch.c
auditfilter.c
auditsc.c
audit: log AUDIT_TIME_* records only from rules
2022-04-15 14:18:04 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-03-11 16:43:42 +01:00
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
random: clear fast pool, crng, and batches in cpuhp bring up
2022-06-22 14:11:12 +02:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
delayacct.c
dma.c
exec_domain.c
exit.c
exit: Use READ_ONCE() for all oops/warn limit reads
2023-02-06 07:52:50 +01:00
extable.c
fail_function.c
fork.c
copy_process(): Move fd_install() out of sighand->siglock critical section
2022-02-23 12:00:00 +01:00
freezer.c
futex.c
mm, futex: fix shared futex pgoff on shmem huge page
2021-06-30 08:47:55 -04:00
gen_kheaders.sh
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kernel: kexec: remove the lock operation of system_transition_mutex
2021-02-03 23:25:56 +01:00
kexec_elf.c
kexec_file.c
kexec_file: drop weak attribute from arch_kexec_apply_relocations[_add]
2022-07-02 16:28:50 +02:00
kexec_internal.h
kheaders.c
kmod.c
kprobes.c
kprobes: Skip clearing aggrprobe's post_handler in kprobe-on-ftrace case
2022-11-25 17:42:21 +01:00
ksysfs.c
kthread.c
kthread: Fix PF_KTHREAD vs to_kthread() race
2021-09-12 08:56:39 +02:00
latencytop.c
Makefile
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
module-internal.h
module.c
module: Don't wait for GOING modules
2023-02-06 07:52:43 +01:00
module_signature.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
module_signing.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
notifier.c
nsproxy.c
padata.c
panic.c
exit: Use READ_ONCE() for all oops/warn limit reads
2023-02-06 07:52:50 +01:00
params.c
pid.c
pid_namespace.c
memcg: enable accounting for pids in nested pid namespaces
2021-09-22 12:26:37 +02:00
profile.c
profiling: fix shift too large makes kernel panic
2022-08-25 11:18:02 +02:00
ptrace.c
ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
2022-06-14 18:11:24 +02:00
range.c
reboot.c
relay.c
relay: fix type mismatch when allocating memory in relay_create_buf()
2023-01-18 11:40:58 +01:00
resource.c
rseq.c
seccomp.c
seccomp: Invalidate seccomp mode to catch death failures
2022-02-16 12:52:53 +01:00
signal.c
signal handling: don't use BUG_ON() for debugging
2022-07-21 20:59:27 +02:00
smp.c
smp: Fix offline cpu check in flush_smp_call_function_queue()
2022-04-20 09:19:39 +02:00
smpboot.c
kthread: Extract KTHREAD_IS_PER_CPU
2021-02-07 15:35:49 +01:00
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stop_machine.c
sys.c
prlimit: do_prlimit needs to have a speculation check
2023-01-24 07:17:59 +01:00
sys_ni.c
kernel/sys_ni: add compat entry for fadvise64_64
2022-09-05 10:27:38 +02:00
sysctl-test.c
sysctl.c
proc: proc_skip_spaces() shouldn't think it is working on C strings
2022-12-08 11:23:06 +01:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
2021-07-14 16:53:08 +02:00
tsacct.c
taskstats: Cleanup the use of task->exit_code
2022-02-23 11:59:57 +01:00
ucount.c
uid16.c
uid16.h
umh.c
up.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog: export lockup_detector_reconfigure
2022-08-25 11:18:37 +02:00
watchdog_hld.c
workqueue.c
workqueue: don't skip lockdep work dependency in cancel_work_sync()
2022-09-28 11:04:09 +02:00
workqueue_internal.h