kernel-hardening.lists.openwall.com archive mirror
 help / color / mirror / Atom feed
* [kernel-hardening] [linux-next][PATCH v2] mm/slub.c: add a naive detection of double free or corruption
@ 2017-08-11 16:17 Alexander Popov
  2017-08-11 17:26 ` [kernel-hardening] " Christopher Lameter
  0 siblings, 1 reply; 2+ messages in thread
From: Alexander Popov @ 2017-08-11 16:17 UTC (permalink / raw)
  To: Kees Cook, Andrew Morton, Christoph Lameter, Pekka Enberg,
	David Rientjes, Joonsoo Kim, Paul E McKenney, Ingo Molnar,
	Tejun Heo, Andy Lutomirski, Nicolas Pitre, linux-mm,
	Rik van Riel, Tycho Andersen, Alexander Popov, linux-kernel,
	kernel-hardening

Add an assertion similar to "fasttop" check in GNU C Library allocator
as a part of SLAB_FREELIST_HARDENED feature. An object added to a singly
linked freelist should not point to itself. That helps to detect some
double free errors (e.g. CVE-2017-2636) without slub_debug and KASAN.

Signed-off-by: Alexander Popov <alex.popov@linux.com>
---
 mm/slub.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/mm/slub.c b/mm/slub.c
index b9c7f1a..77b2781 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -290,6 +290,10 @@ static inline void set_freepointer(struct kmem_cache *s, void *object, void *fp)
 {
 	unsigned long freeptr_addr = (unsigned long)object + s->offset;
 
+#ifdef CONFIG_SLAB_FREELIST_HARDENED
+	BUG_ON(object == fp); /* naive detection of double free or corruption */
+#endif
+
 	*(void **)freeptr_addr = freelist_ptr(s, fp, freeptr_addr);
 }
 
-- 
2.7.4

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* [kernel-hardening] Re: [linux-next][PATCH v2] mm/slub.c: add a naive detection of double free or corruption
  2017-08-11 16:17 [kernel-hardening] [linux-next][PATCH v2] mm/slub.c: add a naive detection of double free or corruption Alexander Popov
@ 2017-08-11 17:26 ` Christopher Lameter
  0 siblings, 0 replies; 2+ messages in thread
From: Christopher Lameter @ 2017-08-11 17:26 UTC (permalink / raw)
  To: Alexander Popov
  Cc: Kees Cook, Andrew Morton, Pekka Enberg, David Rientjes,
	Joonsoo Kim, Paul E McKenney, Ingo Molnar, Tejun Heo,
	Andy Lutomirski, Nicolas Pitre, linux-mm, Rik van Riel,
	Tycho Andersen, linux-kernel, kernel-hardening

On Fri, 11 Aug 2017, Alexander Popov wrote:

> Add an assertion similar to "fasttop" check in GNU C Library allocator
> as a part of SLAB_FREELIST_HARDENED feature. An object added to a singly
> linked freelist should not point to itself. That helps to detect some
> double free errors (e.g. CVE-2017-2636) without slub_debug and KASAN.

Acked-by: Christoph Lameter <cl@linux.com>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-08-11 17:26 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-08-11 16:17 [kernel-hardening] [linux-next][PATCH v2] mm/slub.c: add a naive detection of double free or corruption Alexander Popov
2017-08-11 17:26 ` [kernel-hardening] " Christopher Lameter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).