Thread (78 messages) flat view 78 messages, 7 authors, 2014-08-19

Re: [PATCH RFC v4 net-next 01/26] net: filter: add "load 64-bit immediate" eBPF instruction

From: Andy Lutomirski <luto@amacapital.net>
Date: 2014-08-13 21:41:58
Also in: linux-api, lkml

On Wed, Aug 13, 2014 at 2:27 PM, H. Peter Anvin [off-list ref] wrote:
On 08/13/2014 02:23 PM, Andy Lutomirski wrote:
quoted
On Wed, Aug 13, 2014 at 2:21 PM, H. Peter Anvin [off-list ref] wrote:
quoted
One thing about this that may be a serious concern: allowing the user to
control 8 contiguous bytes of kernel memory may be a security hazard.
I'm confused.  What kind of memory?  I can control a lot more than 8
bytes of stack very easily.

Or are you concerned about 8 contiguous bytes of *executable* memory?
Yes.  Useful for some kinds of ROP custom gadgets.
Hmm.

I think this is moot on non-SMEP machines.  And I'm not entirely
convinced that it's worth worrying about in general, especially if we
take some care to randomize the location of the JIT mapping.

But yes, gadgets like jumps relative to gs or something along those
lines could make for interesting ROP tools.  But someone will probably
figure out how to turn JIT output into a NOP slide + ROP gadget
regardless, at least on x86.

--Andy
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help