Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp3102682imm; Tue, 4 Sep 2018 15:43:16 -0700 (PDT) X-Google-Smtp-Source: ANB0VdYTFM8I5l5yCIhmTdjuJPxkHbrdnTChDeVt8AWHzjye7AJCvuAIHCjL3aI/smRcjF23eGBB X-Received: by 2002:a62:2983:: with SMTP id p125-v6mr36899019pfp.128.1536100996130; Tue, 04 Sep 2018 15:43:16 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1536100996; cv=none; d=google.com; s=arc-20160816; b=GvDPsbNKY6pI3IQUni4CrF32U4vTULeTBOK2paNMV/xiudneqhzVBS1CWR+85QFxUm Iyffg+jVqziv0XIB5zyN2rXYA0dv80fiG1ulCCiDsSu72F9Yz547+O9XqHcRawxAMJli 6eGM86u6rpVeyJjreeqr48ieYFb/aBbVtjzz/hUrRJnTOI73lS5eYYqxROTpuh8MQL7W 5MjPjdC3MHvQ6jUq2hOQHGNzHd/TqUYMf/e3/WVvJhTNwJSHO5cxlmEGGMtUIQLR5EWC c3WXpgaHisFaDnWV/qB8RJXe3dFvEfR9hv80Q2+IkZna/+s4sYaCF0qaK0u8dZWiQFvC nP9w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=WRxf5DmPmMtFZZR72JRYdG3CXo9dOx3o7ctMlbTTT5I=; b=KkVJAdQlyBVstphF3dPcsrpYL6xV+wf6kOo+KB1AjhbB5SGIONlswdOBQxGP6ew/sn SssEd1izitEcyJWLGy7Db7T3T3YBxdCnuAPt3+IRcz+upDZtV34tXsjRI77g00WDyARH uYOGmn5KHIuU7jInRPy8GjM44J2HzifMvX4f6BbysE0XexIDZFE4Cf5wz9a7n5jS4aEQ FO2UCO1+FTHmvotnMhr/fgZbcYkqWy4Z9Qa5PQm2MJ0x/ZRBivvYUbS3k/yuRPFVUDB+ gQDEhv1QUA0i1L5txyF+RIBGaCF5K4BuxQe2cA5z5bQ+2xzlv0gnOyu3oR5DmDihKEVH dpdQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@osandov-com.20150623.gappssmtp.com header.s=20150623 header.b=whlSVxtI; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id t10-v6si42925pgn.667.2018.09.04.15.43.00; Tue, 04 Sep 2018 15:43:16 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@osandov-com.20150623.gappssmtp.com header.s=20150623 header.b=whlSVxtI; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727155AbeIEDJG (ORCPT + 99 others); Tue, 4 Sep 2018 23:09:06 -0400 Received: from mail-pf1-f195.google.com ([209.85.210.195]:35127 "EHLO mail-pf1-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725825AbeIEDJF (ORCPT ); Tue, 4 Sep 2018 23:09:05 -0400 Received: by mail-pf1-f195.google.com with SMTP id p12-v6so2410466pfh.2 for ; Tue, 04 Sep 2018 15:41:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=osandov-com.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=WRxf5DmPmMtFZZR72JRYdG3CXo9dOx3o7ctMlbTTT5I=; b=whlSVxtIj+wz7sEkVq/rXB5n6G9DR/oaL+Dm9ntMT7iqKpvYpq0CiNwIrf6wX1enXF DuDgX0Dv1awpbME3tLxZPdsvaShqux3aOjByCWdXPZRL+ZKtR08IkHb0dTqq/D6b9qpT iruFyET5PBndZ3845wtRSCQsYb25Eo9P8Lj3xp/rEBTxos3WNGlTYrHVdNmcpc2glWfg nwZvVg5jxF0qB/bdIAALJAFagCNCuGVMBxJ+XeqlbIccZW6MwLBbmCmjWsqUzpB8PV7l 2kH9KNKP8vhAUuplN+E4qq+1kt1VMsbUUX3Wo7/hgSbaKBBly3zW0ygZ44hSuAs5Ob/y OM+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=WRxf5DmPmMtFZZR72JRYdG3CXo9dOx3o7ctMlbTTT5I=; b=MfztbDSbE9OO/Z4aTbyl5rxxbqcRi/seR9pVC+LWI3dcxbJHaa8cFbqIF9zn8RJjaA V0Qp2GaOI49mz/9RcjgSZY+QRZTazCoyXB0cvmB+WVlHlMSOXEVq9dQd4sws9rrQWQLc xZGgwrHwpb8TD7LgKMOGQ9++Tr0Ks8zFkLVyoseHQGWjc2/cQAoZasC7cZGfSefxJqiL GF2Uyopi52f87GKrPar8rStezUrG4aHtBd04n1rYs1yvekfPoJwfFTAGOHQniX4H9mhT c9gMWydWZ2Pbhw7KpEnW6BNXxGWbKHvYEOJm5DFJlosORfOEiixdGLiJNGIM4ABYwiwb K7Uw== X-Gm-Message-State: APzg51AREwfUNnuMdEjQk95Z0gWw/+DXqBr3/5PQxOSuwPzYD83NLAc+ tUfXGm4hoHhLsEoN54n2kD4DUA== X-Received: by 2002:a63:e001:: with SMTP id e1-v6mr7381501pgh.380.1536100912172; Tue, 04 Sep 2018 15:41:52 -0700 (PDT) Received: from vader ([2620:10d:c090:200::7:db7b]) by smtp.gmail.com with ESMTPSA id h85-v6sm79535pfk.71.2018.09.04.15.41.51 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Tue, 04 Sep 2018 15:41:51 -0700 (PDT) Date: Tue, 4 Sep 2018 15:41:50 -0700 From: Omar Sandoval To: Dominique Martinet Cc: Andrew Morton , linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org, Alexey Dobriyan , Eric Biederman , James Morse , Bhupesh Sharma , kernel-team@fb.com Subject: Re: [PATCH v3] proc/kcore: fix invalid memory access in multi-page read optimization Message-ID: <20180904224150.GD24406@vader> References: <1536100545-26905-1-git-send-email-asmadeus@codewreck.org> <1536100702-28706-1-git-send-email-asmadeus@codewreck.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1536100702-28706-1-git-send-email-asmadeus@codewreck.org> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Sep 05, 2018 at 12:38:22AM +0200, Dominique Martinet wrote: > The 'm' kcore_list item could point to kclist_head, and it is incorrect to > look at m->addr / m->size in this case. > There is no choice but to run through the list of entries for every address > if we did not find any entry in the previous iteration > > Reset 'm' to NULL in that case at Omar Sandoval's suggestion. > > Fixes: bf991c2231117 ("proc/kcore: optimize multiple page reads") Reviewed-by: Omar Sandoval Thanks again for catching this! > Signed-off-by: Dominique Martinet > --- > > Sorry, resent v2 because From didn't match sob tag > > fs/proc/kcore.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/fs/proc/kcore.c b/fs/proc/kcore.c > index ad72261ee3fe..578926032880 100644 > --- a/fs/proc/kcore.c > +++ b/fs/proc/kcore.c > @@ -464,6 +464,7 @@ read_kcore(struct file *file, char __user *buffer, size_t buflen, loff_t *fpos) > ret = -EFAULT; > goto out; > } > + m = NULL; > } else if (m->type == KCORE_VMALLOC) { > vread(buf, (char *)start, tsz); > /* we have to zero-fill user buffer even if no read */ > -- > 2.17.1 >