Eugeniu Rosca
79514ef670
ravb: Fix use-after-free on ifconfig eth0 down
...
Commit a47b70ea86 ("ravb: unmap descriptors when freeing rings") has
introduced the issue seen in [1] reproduced on H3ULCB board.
Fix this by relocating the RX skb ringbuffer free operation, so that
swiotlb page unmapping can be done first. Freeing of aligned TX buffers
is not relevant to the issue seen in [1]. Still, reposition TX free
calls as well, to have all kfree() operations performed consistently
_after_ dma_unmap_*()/dma_free_*().
[1] Console screenshot with the problem reproduced:
salvator-x login: root
root@salvator-x:~# ifconfig eth0 up
Micrel KSZ9031 Gigabit PHY e6800000.ethernet-ffffffff:00: \
attached PHY driver [Micrel KSZ9031 Gigabit PHY] \
(mii_bus:phy_addr=e6800000.ethernet-ffffffff:00, irq=235)
IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
root@salvator-x:~#
root@salvator-x:~# ifconfig eth0 down
==================================================================
BUG: KASAN: use-after-free in swiotlb_tbl_unmap_single+0xc4/0x35c
Write of size 1538 at addr ffff8006d884f780 by task ifconfig/1649
CPU: 0 PID: 1649 Comm: ifconfig Not tainted 4.12.0-rc4-00004-g112eb07287d1 #32
Hardware name: Renesas H3ULCB board based on r8a7795 (DT)
Call trace:
[<ffff20000808f11c>] dump_backtrace+0x0/0x3a4
[<ffff20000808f4d4>] show_stack+0x14/0x1c
[<ffff20000865970c>] dump_stack+0xf8/0x150
[<ffff20000831f8b0>] print_address_description+0x7c/0x330
[<ffff200008320010>] kasan_report+0x2e0/0x2f4
[<ffff20000831eac0>] check_memory_region+0x20/0x14c
[<ffff20000831f054>] memcpy+0x48/0x68
[<ffff20000869ed50>] swiotlb_tbl_unmap_single+0xc4/0x35c
[<ffff20000869fcf4>] unmap_single+0x90/0xa4
[<ffff20000869fd14>] swiotlb_unmap_page+0xc/0x14
[<ffff2000080a2974>] __swiotlb_unmap_page+0xcc/0xe4
[<ffff2000088acdb8>] ravb_ring_free+0x514/0x870
[<ffff2000088b25dc>] ravb_close+0x288/0x36c
[<ffff200008aaf8c4>] __dev_close_many+0x14c/0x174
[<ffff200008aaf9b4>] __dev_close+0xc8/0x144
[<ffff200008ac2100>] __dev_change_flags+0xd8/0x194
[<ffff200008ac221c>] dev_change_flags+0x60/0xb0
[<ffff200008ba2dec>] devinet_ioctl+0x484/0x9d4
[<ffff200008ba7b78>] inet_ioctl+0x190/0x194
[<ffff200008a78c44>] sock_do_ioctl+0x78/0xa8
[<ffff200008a7a128>] sock_ioctl+0x110/0x3c4
[<ffff200008365a70>] vfs_ioctl+0x90/0xa0
[<ffff200008365dbc>] do_vfs_ioctl+0x148/0xc38
[<ffff2000083668f0>] SyS_ioctl+0x44/0x74
[<ffff200008083770>] el0_svc_naked+0x24/0x28
The buggy address belongs to the page:
page:ffff7e001b6213c0 count:0 mapcount:0 mapping: (null) index:0x0
flags: 0x4000000000000000()
raw: 4000000000000000 0000000000000000 0000000000000000 00000000ffffffff
raw: 0000000000000000 ffff7e001b6213e0 0000000000000000 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff8006d884f680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff8006d884f700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff8006d884f780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff8006d884f800: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff8006d884f880: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
Disabling lock debugging due to kernel taint
root@salvator-x:~#
Fixes: a47b70ea86 ("ravb: unmap descriptors when freeing rings")
Signed-off-by: Eugeniu Rosca <erosca@de.adit-jv.com>
Acked-by: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-06-06 16:02:22 -04:00
arch
ARM: dts: imx6ul-14x14-evk: Add ksz8081 phy properties
2017-06-01 15:02:30 -04:00
block
Merge branch 'nvme-4.12' of git://git.infradead.org/nvme into for-linus
2017-05-26 09:11:19 -06:00
certs
scripts/spelling.txt: add "intialise(d)" pattern and fix typo instances
2017-05-08 17:15:13 -07:00
crypto
crypto: skcipher - Add missing API setkey checks
2017-05-18 13:04:05 +08:00
Documentation
net: Update TCP congestion control documentation
2017-06-05 10:53:24 -04:00
drivers
ravb: Fix use-after-free on ifconfig eth0 down
2017-06-06 16:02:22 -04:00
firmware
fs
Changed since last update:
2017-05-26 12:13:08 -07:00
include
net: Update TCP congestion control documentation
2017-06-05 10:53:24 -04:00
init
Merge branch 'core-rcu-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2017-05-10 10:30:46 -07:00
ipc
mm: introduce kv[mz]alloc helpers
2017-05-08 17:15:12 -07:00
kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
2017-05-26 13:51:01 -07:00
lib
test_bpf: Add a couple of tests for BPF_JSGE.
2017-05-25 14:37:56 -04:00
mm
mm: vmscan: scan until it finds eligible pages
2017-05-12 15:57:16 -07:00
net
net/ipv6: Fix CALIPSO causing GPF with datagram support
2017-06-06 15:18:20 -04:00
samples
samples/bpf: run cleanup routines when receiving SIGTERM
2017-05-11 21:43:30 -04:00
scripts
DeviceTree fixes for 4.12-rc:
2017-05-19 15:03:24 -07:00
security
Merge branch 'work.misc' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs
2017-05-09 09:12:53 -07:00
sound
sound fixes for 4.12-rc3
2017-05-26 09:03:09 -07:00
tools
bpf: add various verifier test cases
2017-05-25 13:44:28 -04:00
usr
virt
KVM: arm/arm64: Hold slots_lock when unregistering kvm io bus devices
2017-05-18 11:18:16 +02:00
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
power supply and reset changes for the v4.12 series (part 2)
2017-05-12 12:02:21 -07:00
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
MAINTAINERS: Move mlx5 rdma header file to IB driver charge
2017-05-30 14:18:15 -04:00
Makefile
Linux 4.12-rc2
2017-05-21 19:30:23 -07:00
README