Liangyan
d63f00ec90
tracing: Correct the length check which causes memory corruption
commit 3e08a9f9760f4a70d633c328a76408e62d6f80a3 upstream.
We've suffered from severe kernel crashes due to memory corruption on
our production environment, like,
Call Trace:
[1640542.554277] general protection fault: 0000 [#1] SMP PTI
[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G
[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190
[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286
[1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX:
0000000006e931bf
[1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI:
ffff9a45ff004300
[1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09:
0000000000000000
[1640542.561670] R10: 0000000000000000 R11: 0000000000000000 R12:
ffffffff9a20608d
[1640542.562366] R13: ffff9a45ff004300 R14: ffff9a45ff004300 R15:
696c662f65636976
[1640542.563128] FS: 00007f45d7c6f740(0000) GS:ffff9a45ff840000(0000)
knlGS:0000000000000000
[1640542.563937] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[1640542.564557] CR2: 00007f45d71311a0 CR3: 000000189d63e004 CR4:
00000000003606e0
[1640542.565279] DR0: 0000000000000000 DR1: 0000000000000000 DR2:
0000000000000000
[1640542.566069] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:
0000000000000400
[1640542.566742] Call Trace:
[1640542.567009] anon_vma_clone+0x5d/0x170
[1640542.567417] __split_vma+0x91/0x1a0
[1640542.567777] do_munmap+0x2c6/0x320
[1640542.568128] vm_munmap+0x54/0x70
[1640542.569990] __x64_sys_munmap+0x22/0x30
[1640542.572005] do_syscall_64+0x5b/0x1b0
[1640542.573724] entry_SYSCALL_64_after_hwframe+0x44/0xa9
[1640542.575642] RIP: 0033:0x7f45d6e61e27
James Wang has reproduced it stably on the latest 4.19 LTS.
After some debugging, we finally proved that it's due to ftrace
buffer out-of-bound access using a debug tool as follows:
[ 86.775200] BUG: Out-of-bounds write at addr 0xffff88aefe8b7000
[ 86.780806] no_context+0xdf/0x3c0
[ 86.784327] __do_page_fault+0x252/0x470
[ 86.788367] do_page_fault+0x32/0x140
[ 86.792145] page_fault+0x1e/0x30
[ 86.795576] strncpy_from_unsafe+0x66/0xb0
[ 86.799789] fetch_memory_string+0x25/0x40
[ 86.804002] fetch_deref_string+0x51/0x60
[ 86.808134] kprobe_trace_func+0x32d/0x3a0
[ 86.812347] kprobe_dispatcher+0x45/0x50
[ 86.816385] kprobe_ftrace_handler+0x90/0xf0
[ 86.820779] ftrace_ops_assist_func+0xa1/0x140
[ 86.825340] 0xffffffffc00750bf
[ 86.828603] do_sys_open+0x5/0x1f0
[ 86.832124] do_syscall_64+0x5b/0x1b0
[ 86.835900] entry_SYSCALL_64_after_hwframe+0x44/0xa9
commit b220c049d519 ("tracing: Check length before giving out
the filter buffer") adds length check to protect trace data
overflow introduced in 0fc1b09ff1, seems that this fix can't prevent
overflow entirely, the length check should also take the sizeof
entry->array[0] into account, since this array[0] is filled the
length of trace data and occupy addtional space and risk overflow.
Link: https://lkml.kernel.org/r/20210607125734.1770447-1-liangyan.peng@linux.alibaba.com
Cc: stable@vger.kernel.org
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Xunlei Pang <xlpang@linux.alibaba.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Fixes: b220c049d519 ("tracing: Check length before giving out the filter buffer")
Reviewed-by: Xunlei Pang <xlpang@linux.alibaba.com>
Reviewed-by: yinbinbin <yinbinbin@alibabacloud.com>
Reviewed-by: Wetp Zhang <wetp.zy@linux.alibaba.com>
Tested-by: James Wang <jnwang@linux.alibaba.com>
Signed-off-by: Liangyan <liangyan.peng@linux.alibaba.com>
Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2021-06-16 11:59:46 +02:00 |
| .. |
|
bpf
|
bpf: No need to simulate speculative domain for immediates
|
2021-05-28 13:10:26 +02:00 |
|
cgroup
|
cgroup1: don't allow '\n' in renaming
|
2021-06-16 11:59:40 +02:00 |
|
configs
|
|
|
|
debug
|
kdb: Make memory allocations more robust
|
2021-03-04 10:26:10 +01:00 |
|
dma
|
swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb"
|
2020-11-18 19:20:32 +01:00 |
|
events
|
perf: Fix data race between pin_count increment/decrement
|
2021-06-16 11:59:44 +02:00 |
|
gcov
|
gcov: re-fix clang-11+ support
|
2021-04-14 08:24:10 +02:00 |
|
irq
|
genirq/matrix: Prevent allocation counter corruption
|
2021-05-11 14:04:05 +02:00 |
|
livepatch
|
|
|
|
locking
|
locking/mutex: clear MUTEX_FLAGS if wait_list is empty due to signal
|
2021-05-26 12:05:15 +02:00 |
|
power
|
PM: EM: postpone creating the debugfs dir till fs_initcall
|
2021-03-30 14:35:28 +02:00 |
|
printk
|
printk: fix deadlock when kernel panic
|
2021-03-04 10:26:50 +01:00 |
|
rcu
|
rcu/nocb: Perform deferred wake up before last idle's need_resched() check
|
2021-03-04 10:26:47 +01:00 |
|
sched
|
sched/fair: Make sure to update tg contrib for blocked load
|
2021-06-16 11:59:44 +02:00 |
|
time
|
posix-timers: Preserve return value in clock_adjtime32()
|
2021-05-11 14:04:04 +02:00 |
|
trace
|
tracing: Correct the length check which causes memory corruption
|
2021-06-16 11:59:46 +02:00 |
|
.gitignore
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
acct.c
|
|
|
|
async.c
|
|
|
|
audit.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit.h
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit_fsnotify.c
|
|
|
|
audit_tree.c
|
|
|
|
audit_watch.c
|
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
|
2020-10-01 13:17:32 +02:00 |
|
auditfilter.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
auditsc.c
|
|
|
|
backtracetest.c
|
|
|
|
bounds.c
|
|
|
|
capability.c
|
|
|
|
compat.c
|
|
|
|
configs.c
|
|
|
|
context_tracking.c
|
|
|
|
cpu.c
|
kernel/cpu: add arch override for clear_tasks_mm_cpumask() mm handling
|
2020-12-30 11:50:56 +01:00 |
|
cpu_pm.c
|
kernel/cpu_pm: Fix uninitted local in cpu_pm
|
2020-06-22 09:31:22 +02:00 |
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
keys: Fix request_key() cache
|
2020-01-17 19:48:42 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
exec_domain.c
|
|
|
|
exit.c
|
don't dump the threads that had been already exiting when zapped.
|
2020-11-18 19:20:31 +01:00 |
|
extable.c
|
|
|
|
fail_function.c
|
fail_function: Remove a redundant mutex unlock
|
2020-11-24 13:29:18 +01:00 |
|
fork.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
freezer.c
|
Revert "libata, freezer: avoid block device removal while system is frozen"
|
2019-10-06 09:11:37 -06:00 |
|
futex.c
|
Revert 337f13046f ("futex: Allow FUTEX_CLOCK_REALTIME with FUTEX_WAIT op")
|
2021-05-11 14:04:16 +02:00 |
|
gen_kheaders.sh
|
kbuild: add variables for compression tools
|
2020-09-03 11:27:10 +02:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
|
|
|
irq_work.c
|
|
|
|
jump_label.c
|
|
|
|
kallsyms.c
|
kallsyms: Refactor kallsyms_show_value() to take cred
|
2020-07-16 08:16:44 +02:00 |
|
kcmp.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
|
|
|
kcov.c
|
|
|
|
kexec.c
|
|
|
|
kexec_core.c
|
kernel: kexec: remove the lock operation of system_transition_mutex
|
2021-02-03 23:25:56 +01:00 |
|
kexec_elf.c
|
|
|
|
kexec_file.c
|
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
|
2021-05-19 10:08:28 +02:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
|
|
|
kmod.c
|
kmod: make request_module() return an error when autoloading is disabled
|
2020-04-17 10:50:22 +02:00 |
|
kprobes.c
|
tracing/kprobe: Fix to support kretprobe events on unloaded modules
|
2021-02-13 13:52:54 +01:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread: Extract KTHREAD_IS_PER_CPU
|
2021-02-07 15:35:49 +01:00 |
|
latencytop.c
|
|
|
|
Makefile
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
module-internal.h
|
|
|
|
module.c
|
modules: inherit TAINT_PROPRIETARY_MODULE
|
2021-05-11 14:04:04 +02:00 |
|
module_signature.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
module_signing.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
notifier.c
|
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
|
2020-10-01 13:17:23 +02:00 |
|
nsproxy.c
|
|
|
|
padata.c
|
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
|
2020-06-17 16:40:22 +02:00 |
|
panic.c
|
panic: ensure preemption is disabled during panic()
|
2019-10-07 15:47:19 -07:00 |
|
params.c
|
|
|
|
pid.c
|
|
|
|
pid_namespace.c
|
|
|
|
profile.c
|
|
|
|
ptrace.c
|
ptrace: make ptrace() fail if the tracee changed its pid unexpectedly
|
2021-05-26 12:05:15 +02:00 |
|
range.c
|
|
|
|
reboot.c
|
reboot: fix overflow parsing reboot cpu number
|
2020-11-18 19:20:30 +01:00 |
|
relay.c
|
kernel/relay.c: fix memleak on destroy relay channel
|
2020-08-26 10:40:51 +02:00 |
|
resource.c
|
/dev/mem: Revoke mappings when a driver claims the region
|
2020-06-24 17:50:35 +02:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Add missing return in non-void function
|
2021-03-04 10:26:45 +01:00 |
|
signal.c
|
ptrace: fix task_join_group_stop() for the case when current is traced
|
2020-11-10 12:37:24 +01:00 |
|
smp.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
smpboot.c
|
kthread: Extract KTHREAD_IS_PER_CPU
|
2021-02-07 15:35:49 +01:00 |
|
smpboot.h
|
|
|
|
softirq.c
|
|
|
|
stackleak.c
|
|
|
|
stacktrace.c
|
stacktrace: Don't skip first entry on noncurrent tasks
|
2019-11-04 21:19:25 +01:00 |
|
stop_machine.c
|
stop_machine: Avoid potential race behaviour
|
2019-10-17 12:47:12 +02:00 |
|
sys.c
|
kernel/sys.c: avoid copying possible padding bytes in copy_to_user
|
2020-10-01 13:17:23 +02:00 |
|
sys_ni.c
|
|
|
|
sysctl-test.c
|
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
|
2020-10-01 13:17:10 +02:00 |
|
sysctl.c
|
sysctl.c: fix underflow value setting risk in vm_table
|
2021-03-17 17:03:45 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
taskstats: fix data-race
|
2020-01-09 10:19:54 +01:00 |
|
test_kprobes.c
|
|
|
|
torture.c
|
|
|
|
tracepoint.c
|
tracepoint: Do not fail unregistering a probe due to memory failure
|
2021-03-04 10:26:32 +01:00 |
|
tsacct.c
|
|
|
|
ucount.c
|
|
|
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
usermodehelper: reset umask to default before executing user process
|
2020-10-14 10:32:58 +02:00 |
|
up.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog/softlockup: Enforce that timestamp is valid on boot
|
2020-02-24 08:36:52 +01:00 |
|
watchdog_hld.c
|
|
|
|
workqueue.c
|
wq: handle VM suspension in stall detection
|
2021-06-16 11:59:35 +02:00 |
|
workqueue_internal.h
|
|
|