Received: by 10.192.165.148 with SMTP id m20csp4928586imm; Tue, 8 May 2018 17:48:07 -0700 (PDT) X-Google-Smtp-Source: AB8JxZq7G2k+2w+ZcpE+dZVldeOFSsisVly1xaWImT0yAK0gvq3WtK5if95pk3+nph+i289LpYng X-Received: by 2002:a17:902:3225:: with SMTP id y34-v6mr44462200plb.180.1525826887145; Tue, 08 May 2018 17:48:07 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1525826887; cv=none; d=google.com; s=arc-20160816; b=EjlAaamiLnN0d6PD9cDylM6wIgz2IaGLSz1O4KMWtWt3P9QgxSr0NULIS+xLAAixPK /GZtTxzg2V3LZ9vmc9rS+Du2ccGxSRC//ElR0RS9yc7HVsjELTFYwecXQCRJYVvcKMSB naiZvXHAbwBThgLpfNpmdgimaL7pEvZsqd1gHmFBlgKFC4NMG4yMyCjZTbe4TpdSovqf 4HobgFszU4RZE72nteK4uxPPoVxEiFrCgN0ZbuE6Zz3gtQ0TgyQKxaEDq37It/w7cihm ylWms06hfLC38fyyJUD0p2RJv2TDvqTBFpCNfOJAqQRVoNZIK7IcYjZ4svkrFt7GWbq4 ggRw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:cc:to:from:dkim-signature:arc-authentication-results; bh=kacq6440mdTwv10+JXG8+ILiqdEXJe+Qny7L57GcEUI=; b=lehKXEpMDXgLV6i63yFyNZ7sDvA2j6+MSKhGVLa1AKzhhdrvCSUHcEh94DerVBRna1 21LppsJ4CBtryKwlzeEBu+LZld7KmaDfAcPT7EF0UfGDn3/pTcuNPOj2UQavg084+Y3H l0HU2Q14XSHH4pUpmwLAhw9l2HtBNAzKyL422ZO+dJeikCv7CXqtaRLGBVF4ywWRBtMb 66xs11nG1EAM7DXIetmuCVpGmSPh9UXH8k+UgYcGJfYnB76tuxclIKjcpEeX+7GGKiaU J5BmCsQ1gXYvGZvInoEmf61TYXvqbf+s9wVBwFHowabv394SMvfmOMWBnGGR6I38Kuq5 0Zcw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=HrIc2zBp; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id q7-v6si11014778pgv.658.2018.05.08.17.47.52; Tue, 08 May 2018 17:48:07 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=HrIc2zBp; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933507AbeEIArK (ORCPT + 99 others); Tue, 8 May 2018 20:47:10 -0400 Received: from mail-pl0-f68.google.com ([209.85.160.68]:36233 "EHLO mail-pl0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S933361AbeEIAmp (ORCPT ); Tue, 8 May 2018 20:42:45 -0400 Received: by mail-pl0-f68.google.com with SMTP id v24-v6so3227129plo.3 for ; Tue, 08 May 2018 17:42:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=kacq6440mdTwv10+JXG8+ILiqdEXJe+Qny7L57GcEUI=; b=HrIc2zBpMlKCaD303NPVf5xNwccD63d6byjHONBlTfRaozEoYFQVPWYnAICxIJoZyK Ok6aHjkCIS7J4kJZMId6UzdfKJEOk1zxh1b3LDrGTQk/dv7Ae4Czh2QfOBmaEQPH+27N H0zjttfhDbQq889l8qPS9qYT5Lm9CgPoRqwas= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=kacq6440mdTwv10+JXG8+ILiqdEXJe+Qny7L57GcEUI=; b=UPXq/QP7T4yz8yl/e5Dock+Z/8/9WGS52Drf3yX0EBao2i8UwvhPioc8OXPBgJp6Od hNBrIUDIjxXDpXWvqLCCWrQF0kIY6WnsAJdRJiEakRQHbznJ87YpdiU92dxzjLISlCr/ hHP52wVjQ22rhx+8/V3qYRKj43hf8r8+HKnwBf/zwsGtWEwzFEyHPBjTv0W0Y8f0/nW0 FRKJydNrSSqptoWluy6AYO1oSuIjlKSfdey7kvZlX92WRKsA3TlcTAbX+0GEruKk7shB YrBp99+gq5TBOns9RXgo3iiCnlhroaYJ5PUbiskw0Q8ONeajLgHUMfuz/X3vftUkuN1P 75tg== X-Gm-Message-State: ALQs6tAAnETZUAt5hK2i2Vgz0XRQkpackTH2wjUPnAxUyITJ8+qAdjFq LSLJdv0Qi06AEk2WRJVt5T6IZg== X-Received: by 2002:a17:902:be0e:: with SMTP id r14-v6mr11498583pls.158.1525826564784; Tue, 08 May 2018 17:42:44 -0700 (PDT) Received: from www.outflux.net (173-164-112-133-Oregon.hfc.comcastbusiness.net. [173.164.112.133]) by smtp.gmail.com with ESMTPSA id d186sm2072694pfa.79.2018.05.08.17.42.41 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Tue, 08 May 2018 17:42:43 -0700 (PDT) From: Kees Cook To: Matthew Wilcox Cc: Kees Cook , Rasmus Villemoes , linux-kernel@vger.kernel.org, linux-mm@kvack.org, kernel-hardening@lists.openwall.com Subject: [PATCH 05/13] mm: Use array_size() helpers for kvmalloc() Date: Tue, 8 May 2018 17:42:21 -0700 Message-Id: <20180509004229.36341-6-keescook@chromium.org> X-Mailer: git-send-email 2.17.0 In-Reply-To: <20180509004229.36341-1-keescook@chromium.org> References: <20180509004229.36341-1-keescook@chromium.org> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Instead of open-coded multiplication, use the new array_size() helper to detect overflow in kvmalloc()-family functions. Signed-off-by: Kees Cook --- include/linux/mm.h | 6 +++--- include/linux/vmalloc.h | 1 + 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/include/linux/mm.h b/include/linux/mm.h index 1ac1f06a4be6..c97ed9aa3412 100644 --- a/include/linux/mm.h +++ b/include/linux/mm.h @@ -25,6 +25,7 @@ #include #include #include +#include struct mempolicy; struct anon_vma; @@ -560,10 +561,9 @@ static inline void *kvzalloc(size_t size, gfp_t flags) static inline void *kvmalloc_array(size_t n, size_t size, gfp_t flags) { - if (size != 0 && n > SIZE_MAX / size) - return NULL; + size_t bytes = array_size(n, size); - return kvmalloc(n * size, flags); + return kvmalloc(bytes, flags); } extern void kvfree(const void *addr); diff --git a/include/linux/vmalloc.h b/include/linux/vmalloc.h index 1e5d8c392f15..398e9c95cd61 100644 --- a/include/linux/vmalloc.h +++ b/include/linux/vmalloc.h @@ -8,6 +8,7 @@ #include #include /* pgprot_t */ #include +#include struct vm_area_struct; /* vma defining user mapping in mm_types.h */ struct notifier_block; /* in notifier.h */ -- 2.17.0