Re: [PATCH mm] VFS: seq_file: ensure ->from is valid.
From: Kees Cook <hidden>
Date: 2018-07-09 18:16:19
Also in:
linux-fsdevel, lkml
From: Kees Cook <hidden>
Date: 2018-07-09 18:16:19
Also in:
linux-fsdevel, lkml
On Fri, Jul 6, 2018 at 8:29 PM, NeilBrown [off-list ref] wrote:
Previous patch ("VFS: simplify seq_file iteration code and interface")
removed code to set ->from to zero when ->count is zero, as ->from is
dead at that time. However it didn't ensure ->from was set properly
whenever ->count becomes non-zero.
This can only happen when ->show() is called. Of the three places it
is called one already has ->from set to zero. The other two are
fixed by setting from to zero after fully flushing the buffer (at which
point ->count will also be zero).
Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: NeilBrown <redacted>I *think* this solves this report, which looks very much like Jann's reproducer: https://syzkaller.appspot.com/bug?extid=4b712dce5cbce6700f27 -Kees -- Kees Cook Pixel Security -- To unsubscribe from this list: send the line "unsubscribe linux-doc" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html