Eric W. Biederman
5f2d04139a
signal: Extend exec_id to 64bits
...
commit d1e7fd6462ca9fc76650fbe6ca800e35b24267da upstream.
Replace the 32bit exec_id with a 64bit exec_id to make it impossible
to wrap the exec_id counter. With care an attacker can cause exec_id
wrap and send arbitrary signals to a newly exec'd parent. This
bypasses the signal sending checks if the parent changes their
credentials during exec.
The severity of this problem can been seen that in my limited testing
of a 32bit exec_id it can take as little as 19s to exec 65536 times.
Which means that it can take as little as 14 days to wrap a 32bit
exec_id. Adam Zabrocki has succeeded wrapping the self_exe_id in 7
days. Even my slower timing is in the uptime of a typical server.
Which means self_exec_id is simply a speed bump today, and if exec
gets noticably faster self_exec_id won't even be a speed bump.
Extending self_exec_id to 64bits introduces a problem on 32bit
architectures where reading self_exec_id is no longer atomic and can
take two read instructions. Which means that is is possible to hit
a window where the read value of exec_id does not match the written
value. So with very lucky timing after this change this still
remains expoiltable.
I have updated the update of exec_id on exec to use WRITE_ONCE
and the read of exec_id in do_notify_parent to use READ_ONCE
to make it clear that there is no locking between these two
locations.
Link: https://lore.kernel.org/kernel-hardening/20200324215049.GA3710@pi3.com.pl
Fixes: 2.3.23pre2
Cc: stable@vger.kernel.org
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-04-17 10:50:12 +02:00
..
bpf
bpf: Explicitly memset some bpf info structures declared on the stack
2020-04-02 15:11:01 +02:00
cgroup
cgroup1: don't call release_agent when it is ""
2020-04-01 11:01:51 +02:00
configs
debug
kgdb: don't use a notifier to enter kgdb at panic; call directly
2019-09-25 17:51:40 -07:00
dma
dma-mapping: Fix dma_pgprot() for unencrypted coherent pages
2020-04-17 10:50:01 +02:00
events
perf/core: Fix mlock accounting in perf_mmap()
2020-02-11 04:35:54 -08:00
gcov
Revert "um: Enable CONFIG_CONSTRUCTORS"
2020-02-01 09:34:53 +00:00
irq
genirq/debugfs: Add missing sanity checks to interrupt injection
2020-04-17 10:50:11 +02:00
livepatch
livepatch: Nullify obj->mod in klp_module_coming()'s error path
2019-08-19 13:03:37 +02:00
locking
locking/lockdep: Avoid recursion in lockdep_count_{for,back}ward_deps()
2020-04-17 10:50:05 +02:00
power
ACPI: PM: s2idle: Avoid possible race related to the EC GPE
2020-02-19 19:52:56 +01:00
printk
printk: fix exclusive_console replaying
2020-02-24 08:36:24 +01:00
rcu
rcu: Allow only one expedited GP to run concurrently with wakeups
2020-03-05 16:43:50 +01:00
sched
sched/fair: Fix enqueue_task_fair warning
2020-04-17 10:50:11 +02:00
time
time/sched_clock: Expire timer in hardirq context
2020-04-17 10:50:02 +02:00
trace
bpf: Fix deadlock with rq_lock in bpf_send_signal()
2020-04-17 10:49:57 +02:00
.gitignore
acct.c
async.c
audit.c
audit: always check the netlink payload length in audit_receive_msg()
2020-03-05 16:43:42 +01:00
audit.h
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit_get_nd(): don't unlock parent too early
2019-11-10 11:56:55 -05:00
auditfilter.c
audit: fix error handling in audit_data_to_entry()
2020-03-05 16:43:42 +01:00
auditsc.c
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Ignore pm_wakeup_pending() for disable_nonboot_cpus()
2020-04-17 10:50:11 +02:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
keys: Fix request_key() cache
2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
elfcore.c
kernel/elfcore.c: include proper prototypes
2019-09-25 17:51:39 -07:00
exec_domain.c
exit.c
exit: panic before exit_mm() on global init exit
2020-01-09 10:20:01 +01:00
extable.c
extable: Add function to search only kernel exception table
2019-08-21 22:23:48 +10:00
fail_function.c
fork.c
mm: fork: fix kernel_stack memcg stats for various stack implementations
2020-04-01 11:02:03 +02:00
freezer.c
Revert "libata, freezer: avoid block device removal while system is frozen"
2019-10-06 09:11:37 -06:00
futex.c
futex: Unbreak futex hashing
2020-03-25 08:25:58 +01:00
gen_kheaders.sh
kheaders: substituting --sort in archive creation
2019-10-17 09:08:19 +09:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
jump_label: Don't warn on __exit jump entries
2019-08-29 15:10:10 +01:00
kallsyms.c
kallsyms: Don't let kallsyms_lookup_size_offset() fail on retrieving the first symbol
2019-08-27 16:19:56 +01:00
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_load: Disable at runtime if the kernel is locked down
2019-08-19 21:54:15 -07:00
kexec_core.c
kexec: bail out upon SIGKILL when allocating memory.
2019-09-25 17:51:40 -07:00
kexec_elf.c
kexec_elf: support 32 bit ELF files
2019-09-06 23:58:44 +02:00
kexec_file.c
Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
2019-09-28 08:14:15 -07:00
kexec_internal.h
kheaders.c
kmod.c
kprobes.c
kprobes: Fix optimize_kprobe()/unoptimize_kprobe() cancellation logic
2020-03-12 13:00:09 +01:00
ksysfs.c
kthread.c
kthread: make __kthread_queue_delayed_work static
2019-10-16 09:20:58 -07:00
latencytop.c
Makefile
Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity
2019-09-27 19:37:27 -07:00
module-internal.h
module.c
module: avoid setting info->name early in case we can fall back to info->mod->name
2020-02-24 08:36:54 +01:00
module_signature.c
module_signing.c
notifier.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
nsproxy.c
padata.c
padata: always acquire cpu_hotplug_lock before pinst->lock
2020-04-08 09:08:47 +02:00
panic.c
panic: ensure preemption is disabled during panic()
2019-10-07 15:47:19 -07:00
params.c
lockdown: Lock down module params that specify hardware parameters (eg. ioport)
2019-08-19 21:54:16 -07:00
pid.c
pid_namespace.c
profile.c
ptrace.c
ptrace: reintroduce usage of subjective credentials in ptrace_has_cap()
2020-01-23 08:22:36 +01:00
range.c
reboot.c
relay.c
resource.c
mm/memory_hotplug.c: use PFN_UP / PFN_DOWN in walk_system_ram_range()
2019-09-24 15:54:09 -07:00
rseq.c
seccomp.c
seccomp: Add missing compat_ioctl for notify
2020-04-17 10:50:09 +02:00
signal.c
signal: Extend exec_id to 64bits
2020-04-17 10:50:12 +02:00
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stacktrace: Don't skip first entry on noncurrent tasks
2019-11-04 21:19:25 +01:00
stop_machine.c
stop_machine: Avoid potential race behaviour
2019-10-17 12:47:12 +02:00
sys.c
Merge branch 'timers-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2019-09-17 12:35:15 -07:00
sys_ni.c
sysctl.c
kernel: sysctl: make drop_caches write-only
2020-01-04 19:18:32 +01:00
sysctl_binary.c
task_work.c
taskstats.c
taskstats: fix data-race
2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
up.c
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog/softlockup: Enforce that timestamp is valid on boot
2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c
workqueue: don't use wq_select_unbound_cpu() for bound works
2020-03-18 07:17:50 +01:00
workqueue_internal.h