From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mga11.intel.com ([192.55.52.93]:13761 "EHLO mga11.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2390777AbeIUU7m (ORCPT ); Fri, 21 Sep 2018 16:59:42 -0400 From: Yu-cheng Yu Subject: [RFC PATCH v4 25/27] mm/mmap: Prevent Shadow Stack VMA merges Date: Fri, 21 Sep 2018 08:03:49 -0700 Message-ID: <20180921150351.20898-26-yu-cheng.yu@intel.com> In-Reply-To: <20180921150351.20898-1-yu-cheng.yu@intel.com> References: <20180921150351.20898-1-yu-cheng.yu@intel.com> Sender: linux-arch-owner@vger.kernel.org List-ID: To: x86@kernel.org, "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-api@vger.kernel.org, Arnd Bergmann , Andy Lutomirski , Balbir Singh , Cyrill Gorcunov , Dave Hansen , Florian Weimer , "H.J. Lu" , Jann Horn , Jonathan Corbet , Kees Cook , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V. Shankar" , Vedvyas Shanbhogue Cc: Yu-cheng Yu Message-ID: <20180921150349.iM8hJxusNTc0RGsZqMDC64h-SKDn4u0FSNdv_e0v1Ug@z> Function returns could unwind stacks beyond its allocated area. We do not merge shadow stack areas. This and VMA guards prevent shadow stack underflow. Signed-off-by: Yu-cheng Yu --- mm/mmap.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/mm/mmap.c b/mm/mmap.c index de2d0faa1c61..fa581ced3f56 100644 --- a/mm/mmap.c +++ b/mm/mmap.c @@ -1123,6 +1123,12 @@ struct vm_area_struct *vma_merge(struct mm_struct *mm, if (vm_flags & VM_SPECIAL) return NULL; + /* + * Do not merge shadow stack areas. + */ + if (vm_flags & VM_SHSTK) + return NULL; + if (prev) next = prev->vm_next; else -- 2.17.1