2013-03-11 19:25:26

by Kees Cook

[permalink] [raw]
Subject: [PATCH] drm/i915: restrict kernel address leak in debugfs

Masks kernel address info-leak in object dumps with the %pK suffix,
so they cannot be used to target kernel memory corruption attacks if
the kptr_restrict sysctl is set.

Signed-off-by: Kees Cook <[email protected]>
Cc: [email protected]
---
drivers/gpu/drm/i915/i915_debugfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/i915_debugfs.c b/drivers/gpu/drm/i915/i915_debugfs.c
index aae3148..7299ea4 100644
--- a/drivers/gpu/drm/i915/i915_debugfs.c
+++ b/drivers/gpu/drm/i915/i915_debugfs.c
@@ -103,7 +103,7 @@ static const char *cache_level_str(int type)
static void
describe_obj(struct seq_file *m, struct drm_i915_gem_object *obj)
{
- seq_printf(m, "%p: %s%s %8zdKiB %02x %02x %d %d %d%s%s%s",
+ seq_printf(m, "%pK: %s%s %8zdKiB %02x %02x %d %d %d%s%s%s",
&obj->base,
get_pin_flag(obj),
get_tiling_flag(obj),
--
1.7.9.5


--
Kees Cook
Chrome OS Security


2013-03-11 23:18:31

by Daniel Vetter

[permalink] [raw]
Subject: Re: [PATCH] drm/i915: restrict kernel address leak in debugfs

On Mon, Mar 11, 2013 at 12:25:19PM -0700, Kees Cook wrote:
> Masks kernel address info-leak in object dumps with the %pK suffix,
> so they cannot be used to target kernel memory corruption attacks if
> the kptr_restrict sysctl is set.
>
> Signed-off-by: Kees Cook <[email protected]>
> Cc: [email protected]
Picked up for -fixes, thanks for the patch.
-Daniel
--
Daniel Vetter
Software Engineer, Intel Corporation
+41 (0) 79 365 57 48 - http://blog.ffwll.ch