Thread (6 messages) flat view 6 messages, 3 authors, 2012-04-06

Re: sendmmsg: put_user vs __put_user

From: David Miller <davem@davemloft.net>
Date: 2012-04-06 01:01:19
Also in: lkml

From: Andy Lutomirski <redacted>
Date: Thu, 05 Apr 2012 17:14:25 -0700
On 03/30/2012 05:51 PM, David Miller wrote:
quoted
From: Ulrich Drepper <redacted>
Date: Fri, 30 Mar 2012 09:36:11 -0400
quoted
Shouldn't the compat code in the sendmmsg implementation use the same
code as the normal code?  In which case you probably want something
like this:
Compat processes are not able to generate virtual addresses anywhere
near the range where the kernel resides, so the address range
verification done by put_user() is completely superfluous and
therefore not necessary.  The normal exception handling done by the
access is completely sufficient.
I disagree.  The following exploit causes a bogus page fault to a kernel
address.  I think this isn't exploitable right now on x86-64 because the
page fault handler fixes it up, but I wouldn't be surprised if this
crashes or at least warns on some architecture.  (Actually trashing
kernel memory is probably impossible with this on x86-64 chips because
this can only overrun user space by four bytes, and there's a giant gap
of impossible addresses above user space in x86-64.
I can guarentee this doesn't do anything on sparc64 either because
userspace is completely segregated from kernel space in a way that
every single foo_user() call cannot access kernel space no matter
what address it can trick into being passed there.

I still really don't see an issue with this, sorry.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help