Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp4537082imm; Mon, 17 Sep 2018 16:05:10 -0700 (PDT) X-Google-Smtp-Source: ANB0VdaBXHgVKgcHbNOrDPmqbfXH8EoMM15IU35zTYq7EIPG8pAke5EjCXF/zlNEFZ4f52s9jiph X-Received: by 2002:a63:fd06:: with SMTP id d6-v6mr24778685pgh.348.1537225510119; Mon, 17 Sep 2018 16:05:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1537225510; cv=none; d=google.com; s=arc-20160816; b=lAX0T6ol0PWgO7aFshlqv6uUyWzRvSh+2VgsYe1HamWe+VZFlnqv91T5BjHrHVPDDA i4ksh7030xlKvRCWLHGfXgH6GuUp4+xcPOo21w0hT0oo4ycKcn1M33t6dcuyeNJ1sZmR SlSskhyT9lx+VyvodT4Kw4koKEan/Ycph4W+0aZSDARqzTRNw0b3Xlidfd/3HHS2KsHI /HzDhRxZBOETpy0agN6U0kF88hu487T+EuXJ+2K2rTwStLKMKjy17nKggmZzz/Or/5ge aaFW+MBHhaJ+T44P/9CIc0RwyYxKG4Hn9LGds5rM7XCTqkXbuiE+SH/wiIoUOLLvVuWp cbqA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from; bh=54su4QkHrESlTSUBflHQc+GOL+gdlNAy06kLd+gFDdM=; b=WkPWQ5MD88ua08HE4r1fmQ/aPA7WvyL5lRjAhBHCAGRhzHP8RSEEkH7d864P/J+VV2 O8SENqL1BEEOXek4BcPoRlNPbZpqAxInc6adJNgd4W1qb6X8UYaEOM6CyL/fLAjlJLZU 95PBS8krXIS+rET/FwNmlwfyp+PbEtH0GQ/G/z2ng7GVICf7s8MWDWzU5oKNm2kjySt+ 5FODgbj9kiHMvyWTyVDzInXvu8h4SRw572P7qZjwsXZkwkbzUfVKUAIMz7w349ehYmrs pTljZfq2nJC9Et0Lz+y7Xoz0BwjoRjn32oHaMXWJk/CghmnbH4ByzEVZ/h3gRLUWL0CS JVoA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id n10-v6si18730855pfb.316.2018.09.17.16.04.53; Mon, 17 Sep 2018 16:05:10 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730588AbeIREcs (ORCPT + 99 others); Tue, 18 Sep 2018 00:32:48 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:48810 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727202AbeIREcr (ORCPT ); Tue, 18 Sep 2018 00:32:47 -0400 Received: from localhost (li1825-44.members.linode.com [172.104.248.44]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 6F1DFC03; Mon, 17 Sep 2018 23:03:18 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Jinbum Park , Jens Axboe , Sasha Levin Subject: [PATCH 4.14 069/126] pktcdvd: Fix possible Spectre-v1 for pkt_devs Date: Tue, 18 Sep 2018 00:41:57 +0200 Message-Id: <20180917211708.811442655@linuxfoundation.org> X-Mailer: git-send-email 2.19.0 In-Reply-To: <20180917211703.481236999@linuxfoundation.org> References: <20180917211703.481236999@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.14-stable review patch. If anyone has any objections, please let me know. ------------------ From: Jinbum Park [ Upstream commit 55690c07b44a82cc3359ce0c233f4ba7d80ba145 ] User controls @dev_minor which to be used as index of pkt_devs. So, It can be exploited via Spectre-like attack. (speculative execution) This kind of attack leaks address of pkt_devs, [1] It leads an attacker to bypass security mechanism such as KASLR. So sanitize @dev_minor before using it to prevent attack. [1] https://github.com/jinb-park/linux-exploit/ tree/master/exploit-remaining-spectre-gadget/leak_pkt_devs.c Signed-off-by: Jinbum Park Signed-off-by: Jens Axboe Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/block/pktcdvd.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) --- a/drivers/block/pktcdvd.c +++ b/drivers/block/pktcdvd.c @@ -67,7 +67,7 @@ #include #include #include - +#include #include #define DRIVER_NAME "pktcdvd" @@ -2231,6 +2231,8 @@ static struct pktcdvd_device *pkt_find_d { if (dev_minor >= MAX_WRITERS) return NULL; + + dev_minor = array_index_nospec(dev_minor, MAX_WRITERS); return pkt_devs[dev_minor]; }