Thread (11 messages) 11 messages, 4 authors, 2018-07-09

Re: [PATCH mm] VFS: seq_file: ensure ->from is valid.

From: Kees Cook <hidden>
Date: 2018-07-09 18:16:19
Also in: linux-fsdevel, lkml

On Fri, Jul 6, 2018 at 8:29 PM, NeilBrown [off-list ref] wrote:
Previous patch ("VFS: simplify seq_file iteration code and interface")
removed code to set ->from to zero when ->count is zero, as ->from is
dead at that time.  However it didn't ensure ->from was set properly
whenever ->count becomes non-zero.
This can only happen when ->show() is called.  Of the three places it
is called one already has ->from set to zero.  The other two are
fixed by setting from to zero after fully flushing the buffer (at which
point ->count will also be zero).

Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: NeilBrown <redacted>
I *think* this solves this report, which looks very much like Jann's reproducer:

https://syzkaller.appspot.com/bug?extid=4b712dce5cbce6700f27

-Kees

-- 
Kees Cook
Pixel Security
--
To unsubscribe from this list: send the line "unsubscribe linux-doc" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help