Catalin Marinas
95236ae76b
mm: Avoid creating virtual address aliases in brk()/mmap()/mremap()
...
commit dcde237319e626d1ec3c9d8b7613032f0fd4663a upstream.
Currently the arm64 kernel ignores the top address byte passed to brk(),
mmap() and mremap(). When the user is not aware of the 56-bit address
limit or relies on the kernel to return an error, untagging such
pointers has the potential to create address aliases in user-space.
Passing a tagged address to munmap(), madvise() is permitted since the
tagged pointer is expected to be inside an existing mapping.
The current behaviour breaks the existing glibc malloc() implementation
which relies on brk() with an address beyond 56-bit to be rejected by
the kernel.
Remove untagging in the above functions by partially reverting commit
ce18d171cb ("mm: untag user pointers in mmap/munmap/mremap/brk"). In
addition, update the arm64 tagged-address-abi.rst document accordingly.
Link: https://bugzilla.redhat.com/1797052
Fixes: ce18d171cb ("mm: untag user pointers in mmap/munmap/mremap/brk")
Cc: <stable@vger.kernel.org> # 5.4.x-
Cc: Florian Weimer <fweimer@redhat.com>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Reported-by: Victor Stinner <vstinner@redhat.com>
Acked-by: Will Deacon <will@kernel.org>
Acked-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-02-28 17:22:21 +01:00
..
kasan
mm: introduce compound_nr()
2019-09-24 15:54:08 -07:00
backing-dev.c
memcg: fix a crash in wb_workfn when a device disappears
2020-02-11 04:35:11 -08:00
balloon_compaction.c
mm/balloon_compaction: suppress allocation warnings
2019-09-04 07:42:01 -04:00
cleancache.c
cma.c
cma.h
cma_debug.c
compaction.c
mm, compaction: fix wrong pfn handling in __reset_isolation_pfn()
2019-10-14 15:04:01 -07:00
debug.c
mm/debug.c: PageAnon() is true for PageKsm() pages
2019-11-15 18:34:00 -08:00
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
fs: Export generic_fadvise()
2019-08-30 22:43:58 -07:00
failslab.c
filemap.c
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
frame_vector.c
mm: untag user pointers in get_vaddr_frames
2019-09-25 17:51:41 -07:00
frontswap.c
gup.c
mm/gup: fix a misnamed "write" argument, and a related bug
2019-10-19 06:32:32 -04:00
gup_benchmark.c
mm/gup: fix memory leak in __gup_benchmark_ioctl
2020-01-09 10:20:00 +01:00
highmem.c
hmm.c
pagewalk: separate function pointers from iterator data
2019-09-07 04:28:04 -03:00
huge_memory.c
mm/huge_memory.c: thp: fix conflict of above-47bit hint address and PMD alignment
2020-01-23 08:22:39 +01:00
hugetlb.c
mm/hugetlb: defer freeing of huge pages if in non-task context
2020-01-09 10:20:07 +01:00
hugetlb_cgroup.c
mm: hugetlb: switch to css_tryget() in hugetlb_cgroup_charge_cgroup()
2019-11-15 18:34:00 -08:00
hwpoison-inject.c
init-mm.c
mm/init-mm.c: include <linux/mman.h> for vm_committed_as_batch
2019-10-19 06:32:32 -04:00
internal.h
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
interval_tree.c
Kconfig
mm,thp: add read-only THP support for (non-shmem) FS
2019-09-24 15:54:11 -07:00
Kconfig.debug
mm, page_owner, debug_pagealloc: save and dump freeing stack trace
2019-09-24 15:54:08 -07:00
khugepaged.c
mm,thp: recheck each page before collapsing file THP
2019-11-15 18:34:00 -08:00
kmemleak-test.c
kmemleak.c
kmemleak: Do not corrupt the object_list during clean-up
2019-10-14 08:56:16 -07:00
ksm.c
mm/ksm.c: don't WARN if page is still mapped in remove_stable_node()
2019-11-22 09:11:18 -08:00
list_lru.c
maccess.c
uaccess: Add non-pagefault user-space write function
2020-01-17 19:48:40 +01:00
madvise.c
mm: fix trying to reclaim unevictable lru page when calling madvise_pageout
2019-11-15 18:33:59 -08:00
Makefile
mm: silence -Woverride-init/initializer-overrides
2019-09-24 15:54:10 -07:00
memblock.c
mm: memblock: do not enforce current limit for memblock_phys* family
2019-10-19 06:32:32 -04:00
memcontrol.c
mm/memcontrol.c: lost css_put in memcg_expand_shrinker_maps()
2020-02-28 17:22:20 +01:00
memfd.c
mm: page cache: store only head pages in i_pages
2019-09-24 15:54:08 -07:00
memory-failure.c
mm/memory-failure.c: don't access uninitialized memmaps in memory_failure()
2019-10-19 06:32:31 -04:00
memory.c
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
memory_hotplug.c
mm/memory_hotplug: fix remove_memory() lockdep splat
2020-02-11 04:35:12 -08:00
mempolicy.c
mm/mempolicy.c: fix out of bounds write in mpol_parse_str()
2020-02-05 21:22:40 +00:00
mempool.c
memremap.c
mm/memory_hotplug: shrink zones when offlining memory
2020-01-09 10:19:56 +01:00
memtest.c
migrate.c
mm: move_pages: report the number of non-attempted pages
2020-02-11 04:35:13 -08:00
mincore.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
mlock.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
mm_init.c
mmap.c
mm: Avoid creating virtual address aliases in brk()/mmap()/mremap()
2020-02-28 17:22:21 +01:00
mmu_context.c
mmu_gather.c
mm/mmu_gather: invalidate TLB correctly on batch allocation failure and flush
2020-02-11 04:35:42 -08:00
mmu_notifier.c
mm/mmu_notifiers: use the right return code for WARN_ON
2019-11-06 08:47:50 -08:00
mmzone.c
mprotect.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
mremap.c
mm: Avoid creating virtual address aliases in brk()/mmap()/mremap()
2020-02-28 17:22:21 +01:00
msync.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
nommu.c
mm: introduce page_size()
2019-09-24 15:54:08 -07:00
oom_kill.c
mm/oom: fix pgtables units mismatch in Killed process message
2020-01-09 10:19:57 +01:00
page-writeback.c
mm/page-writeback.c: avoid potential division by zero in wb_min_max_ratio()
2020-01-23 08:22:41 +01:00
page_alloc.c
mm/page_alloc.c: fix uninitialized memmaps on a partially populated last section
2020-02-11 04:35:42 -08:00
page_counter.c
page_ext.c
mm, page_owner: fix off-by-one error in __set_page_owner_handle()
2019-10-14 15:04:00 -07:00
page_idle.c
page_io.c
mm/page_io.c: do not free shared swap slots
2019-11-15 18:34:00 -08:00
page_isolation.c
page_owner.c
mm/page_owner: don't access uninitialized memmaps when reading /proc/pagetypeinfo
2019-10-19 06:32:31 -04:00
page_poison.c
mm/page_poison.c: fix a typo in a comment
2019-09-24 15:54:08 -07:00
page_vma_mapped.c
mm: introduce page_size()
2019-09-24 15:54:08 -07:00
pagewalk.c
pagewalk: use lockdep_assert_held for locking validation
2019-09-07 04:28:04 -03:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
percpu: Use struct_size() helper
2019-09-04 13:40:49 -07:00
pgtable-generic.c
process_vm_access.c
readahead.c
rmap.c
mm: include <linux/huge_mm.h> for is_vma_temporary_stack
2019-10-19 06:32:32 -04:00
rodata_test.c
shmem.c
mm/shmem.c: thp, shmem: fix conflict of above-47bit hint address and PMD alignment
2020-01-23 08:22:39 +01:00
shuffle.c
mm: fix -Wmissing-prototypes warnings
2019-10-07 15:47:19 -07:00
shuffle.h
slab.c
mm, debug_pagealloc: don't rely on static keys too early
2020-01-23 08:22:40 +01:00
slab.h
mm: slab: make page_cgroup_ino() to recognize non-compound slab pages properly
2019-11-06 08:47:50 -08:00
slab_common.c
mm: memcg/slab: call flush_memcg_workqueue() only if memcg workqueue is valid
2020-01-23 08:22:39 +01:00
slob.c
mm, sl[aou]b: guarantee natural alignment for kmalloc(power-of-two)
2019-10-07 15:47:20 -07:00
slub.c
mm, debug_pagealloc: don't rely on static keys too early
2020-01-23 08:22:40 +01:00
sparse-vmemmap.c
sparse.c
mm/sparsemem: pfn_to_page is not valid yet on SPARSEMEM
2020-02-28 17:22:20 +01:00
swap.c
mm: introduce MADV_COLD
2019-09-25 17:51:41 -07:00
swap_cgroup.c
swap_slots.c
swap_state.c
mm: page cache: store only head pages in i_pages
2019-09-24 15:54:08 -07:00
swapfile.c
truncate.c
mm/thp: allow dropping THP from page cache
2019-10-19 06:32:33 -04:00
usercopy.c
usercopy: Avoid HIGHMEM pfn warning
2019-09-17 15:20:17 -07:00
userfaultfd.c
util.c
arm64, mm: make randomization selected by generic topdown mmap layout
2019-09-24 15:54:11 -07:00
vmacache.c
vmalloc.c
mm, debug_pagealloc: don't rely on static keys too early
2020-01-23 08:22:40 +01:00
vmpressure.c
mm/vmpressure.c: fix a signedness bug in vmpressure_register_event()
2019-10-07 15:47:19 -07:00
vmscan.c
mm/vmscan.c: don't round up scan size for online memory cgroup
2020-02-28 17:22:20 +01:00
vmstat.c
mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo
2019-11-06 08:47:50 -08:00
workingset.c
z3fold.c
mm/z3fold.c: claim page in the beginning of free
2019-10-07 15:47:19 -07:00
zbud.c
zpool.c
zpool: add malloc_support_movable to zpool_driver
2019-09-24 15:54:12 -07:00
zsmalloc.c
mm/zsmalloc.c: fix the migrated zspage statistics.
2020-01-09 10:19:56 +01:00
zswap.c
zswap: do not map same object twice
2019-09-24 15:54:12 -07:00