2022-08-18 23:32:34

by Steven Rostedt

[permalink] [raw]
Subject: Re: data-race in pcpu_alloc / pcpu_nr_pages

On Thu, 18 Aug 2022 18:29:00 -0400
Abhishek Shah <[email protected]> wrote:

> Hi all,
>
> We found a race involving the *pcpu_nr_populated *variable. We discovered
> that the racing variable is used in meminfo_proc_show
> <https://elixir.bootlin.com/linux/v5.18-rc5/source/fs/proc/meminfo.c#L123>,
> but we were not sure if there were other security-relevant implications of
> this race. Please let us know what you think.

So you see that the number displayed in meminfo can be written to while
it's being read? As it's a long value, it is likely to be accurate (the
value before or after the update). pcpu_nr_pages() is only used to display
the number of pages in meminfo.

I don't see any problem here.

-- Steve


2022-08-22 16:50:25

by Gabriel Ryan

[permalink] [raw]
Subject: Re: data-race in pcpu_alloc / pcpu_nr_pages

Hi Steve,

Makes sense, thanks for taking the time to review this for us!

Best,

Gabe


On Thu, Aug 18, 2022 at 7:28 PM Steven Rostedt <[email protected]> wrote:
>
> On Thu, 18 Aug 2022 18:29:00 -0400
> Abhishek Shah <[email protected]> wrote:
>
> > Hi all,
> >
> > We found a race involving the *pcpu_nr_populated *variable. We discovered
> > that the racing variable is used in meminfo_proc_show
> > <https://urldefense.proofpoint.com/v2/url?u=https-3A__elixir.bootlin.com_linux_v5.18-2Drc5_source_fs_proc_meminfo.c-23L123&d=DwICAg&c=009klHSCxuh5AI1vNQzSO0KGjl4nbi2Q0M1QLJX9BeE&r=EyAJYRJu01oaAhhVVY3o8zKgZvacDAXd_PNRtaqACCo&m=JaafDoHfUv9wBvITwFrxb8GW82J0sFuH-p1ItZM6jxU4b2c4UzG6SAgIIAX_vLz9&s=AHf4mjYOVq3qPnt65oFSjl4kztRIYFGagjntxAqUFWE&e= >,
> > but we were not sure if there were other security-relevant implications of
> > this race. Please let us know what you think.
>
> So you see that the number displayed in meminfo can be written to while
> it's being read? As it's a long value, it is likely to be accurate (the
> value before or after the update). pcpu_nr_pages() is only used to display
> the number of pages in meminfo.
>
> I don't see any problem here.
>
> -- Steve

--
Gabriel Ryan
PhD Candidate at Columbia University