Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp719758imu; Tue, 27 Nov 2018 05:25:36 -0800 (PST) X-Google-Smtp-Source: AFSGD/WDYg1t/pZmg4sp/9WniMxQAnEtHC6LIG5W8HtMi2ydwy1KENT0WYJIA3/n9VC4kKzfigGl X-Received: by 2002:aa7:8286:: with SMTP id s6mr13709209pfm.63.1543325136190; Tue, 27 Nov 2018 05:25:36 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1543325136; cv=none; d=google.com; s=arc-20160816; b=jXzckq38wXctcwxoIbiax9FUN0SNaGTVecLf5Xh1SyaKdIGyscrV8Z328TpM7yhK8K EnZ4hKioRCDGlxMRm+dC9NY+CgmtQjF7bXPM2L+KPsL86YGPn00skJHE2z4g9S8V3uko SVHucEk1JFYnpFvYXXv53x5F1io/D88qGwkuNJ1rxqrx1i0HKp+v2dNB7lsZdeF2kjaP qN91OcfrCexHy7vW1ELxgQxmLJc84a2YhisBc4hNIcVwLSk9SCaEI2AkZxHCIiwDdNWl cjKtY9Udlz6C75zyRbuA7BietC+KKVynjPe2sLopekOi3Et51Tn4qxL4M4U2bwIHgzqd iOSw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :content-language:accept-language:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature; bh=YRJTAq5ejnp0iahKhBOZSYclUGnUmKdF3A4539VZeGI=; b=tGRiZ5tAqJY5VErSdYIPIY/BhlEC8GqPSBD38T9ZbNvhrT9578DZA/XSrQaNep+8pH 1i4mk+ZhuTwXpOIYEOWrHJ6BrgsWM0lY/GAXmHBhI/3sOzBKz1RhPvAJqnWDKIZ3I0hP riMmKFSAuJxmiJoCNTUCnV9mVFRbYuGA3X6goMwF7LlFZXL1ILyBsWHjl71Wub4DNXas I1qEesSuGVl3Rx0choE8WXcxjSf6UfUSjG7SQj9KxGaBZLQUkvBBdkJVXld7JD63nTxP QLVEYOyX5AKcglmRBBa4GZXOBwXjOP6Ug+MLxaGtNb7CADz5B0KyFMyLVNfiP7FZ9Kbs pM7g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@live.com header.s=selector1 header.b=Jk7esfJO; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=live.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j91si4091478pld.395.2018.11.27.05.24.58; Tue, 27 Nov 2018 05:25:36 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@live.com header.s=selector1 header.b=Jk7esfJO; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=live.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730805AbeK0Vcg (ORCPT + 99 others); Tue, 27 Nov 2018 16:32:36 -0500 Received: from mail-oln040092005048.outbound.protection.outlook.com ([40.92.5.48]:22680 "EHLO NAM02-SN1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1729318AbeK0Vcg (ORCPT ); Tue, 27 Nov 2018 16:32:36 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=live.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=YRJTAq5ejnp0iahKhBOZSYclUGnUmKdF3A4539VZeGI=; b=Jk7esfJOx96d7Z+hz9D1NjO1NXh7TG3k/AXbijcdK/pv5jsDpUX/uPn3EDXkFTf9KFSzzzSFb/nu1bOB5iKSx7Is9JK3L5umPEZFIWeU3qPD/jxkLMQwTUPfiMP2B4O5lNbME3l9gpSU6hdeZPiNs0fevtYgkmZISOBjb/2cKxpuA5SUeY8R/hTJ64d34eotnRP69fLQW1OYfF1kNpwRGmQdmxxJEOX7vvscTUUYhHMxbfuAKgN4K+JYhvjubsWvffP17G+rDZVEWdC5KTsr7JMzNMqwyBrUwlc5lymwAI8DljAREQwBL/0i26OHxwJofUfeqYlNe4xHsOHiqQEETg== Received: from BL2NAM02FT015.eop-nam02.prod.protection.outlook.com (10.152.76.58) by BL2NAM02HT134.eop-nam02.prod.protection.outlook.com (10.152.77.76) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1339.15; Tue, 27 Nov 2018 10:34:26 +0000 Received: from BLUPR13MB0289.namprd13.prod.outlook.com (10.152.76.60) by BL2NAM02FT015.mail.protection.outlook.com (10.152.77.167) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1339.15 via Frontend Transport; Tue, 27 Nov 2018 10:34:26 +0000 Received: from BLUPR13MB0289.namprd13.prod.outlook.com ([fe80::eccf:c550:ed97:f1e7]) by BLUPR13MB0289.namprd13.prod.outlook.com ([fe80::eccf:c550:ed97:f1e7%7]) with mapi id 15.20.1382.012; Tue, 27 Nov 2018 10:34:26 +0000 From: Yueyi Li To: "gregkh@linuxfoundation.org" , "w@1wt.eu" CC: "donb@securitymouse.com" , "linux-kernel@vger.kernel.org" , Yueyi Li Subject: [PATCH] lzo: fix ip overrun during compress. Thread-Topic: [PATCH] lzo: fix ip overrun during compress. Thread-Index: AQHUhjzFV7dxiksDcEGXoSZcs8ZKew== Date: Tue, 27 Nov 2018 10:34:26 +0000 Message-ID: Accept-Language: en-US, zh-CN Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-clientproxiedby: HK2PR02CA0183.apcprd02.prod.outlook.com (2603:1096:201:21::19) To BLUPR13MB0289.namprd13.prod.outlook.com (2a01:111:e400:5951::22) x-incomingtopheadermarker: OriginalChecksum:6281897975358AEA616560EEDD9901F8069DDC8BEE81BC78841A979A13398698;UpperCasedChecksum:E737C4767AF0CB68283EA3B91CD3A9D31BD5A8ACD6E56EEEB634C3A6B998E29D;SizeAsReceived:7443;Count:48 x-ms-exchange-messagesentrepresentingtype: 1 x-tmn: [JcM/11DwsaztynpSN12N64EkHJwFsWW2] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;BL2NAM02HT134;6:I0n2/3ZpDyQPeDN5LEBE9Seqav9soYsTyCbo9PVhDpLjuGXCZzGpD/4WzjSjtjV8VWWE+AoM8YXKChSbhfqZhLsCJa307wqHTB/s+GcaeEGMI59QJ3G5IKNRm5viK2+swNft9zO8ltKc/WM/8q63ZgpjuJWXURkfdHEhJ3OqioqTovhVd4SC0XSP93RQtw/KVuCIQe+24ktuBiVyDgVURnTWYRQzU/a7XNZ/KSoQxWdwR9J+pKPuSP5twAa3uwHrFpo+ZeBim4w0uUpdFR2Mmx0xlPNJhBw1l8G+bZUkPS2Lvxqv22uF96pzxwbfKD+CWIhC3S4he05kxggPDRTT/PfX0AoStqacBVHJ+M0h3qBXS9jcvMMhSffFV6it3SrJz2M4CZzmBxqf9jv7yTsbNKiMYzNbU1oiGs3ZpxvXAzlFlRw7h12KoDyJxEB3+kQA6NHHUTT1lnkumCRvVxBndA==;5:qJv/Wto98NLYOLF+ZDKDIKBwlNUUUNEgXV/25kwckHjxr0PRFQBRt5vERwc5iueMWkTblvHWYaKH9e6sbI+iEtqFYNiT6gvq35dy2ta9Na3woNgbwB7BbX2ToPFCLlD5dLHWbI2J4g9kZzqb/RGkmFHoeB+mar9nGhtumXx1jac=;7:vzy7GWAvwQVy/e7FqPHHZ/ErG6kxXpF+Uhf93Ab87DmN8fimOfBsO4UBHIlpJsaAecQm2C+O//9FHlj98E8W1/L2PrBgiVVBdQwHF4FvxpTOUICtk09Hyj/iafsWEPML5VVY6nZt4jvBfzAALwfo7w== x-incomingheadercount: 48 x-eopattributedmessage: 0 x-ms-exchange-slblob-mailprops: mBRmoEB1kyJBHxbiyk7Ffs2iIzsZwIFnzAFwxaCBTyWR3IbAu57r4xUZ7uzPcRfy3b3xe3S8f8Rj0wYXclBsGFg1ExDQ/U5GZxu8OfyBK/TUkq9gBGUXnkozXWTXy0hCuoaRiUItkSZ9zxAfOq+UDqtEFhp0m2m/BrCtFJ6BofpgxwuKpDJ1RtSCwy83sCip/bvF5uAc7GCEkIZ+QbRlmG1xNfW+dth7vaHTHxSy7ryg2AiAdjl3AR6lG7YnxssAMnM86sd5LGRm/n92cgyqwTBWLhVCBVyZDDCUSibIqGZOGrTpRp1MwoechO/cgEJDk57ze346Tj0oihGZZPEiEu4q2EEdbzD9dEMzhrtpRRm/xEadRErnOsMEbt+r/+DOQM4Vpi0pevBYXDmpRRtb9ptq6Lau2m6yVBPdSNDzPo3Uz/loTNl6JS9P76oyB13yRQIAAxbbXkVfGawU2g1InFT0AHkqOv7rWl/X9n07kamWbPRYBNg2QZPocIaq+i0PL55TwUDR7YPBliFqhDvBk6TQ6MHdf893XLggBoTc0mH8pG2vCsqLIu5iFuz+nszqwbqwwzQ1bcvyVDmXHsEy/qukuVJVi5ddrxrDJAGQDdTk93SmQEnZDGRo/WiIXSSH4ZAhZo5qh5prTHRv9enNlRnu9NgwsOpH0prEbQDAK3huXNisyF4odZtvTZBPszkfz5S3q0pujYaWuaAPtDOvawziI1cWKxv5jSuFAH/DWWEnP71+9zGKbwWaU9MRIp5vSXGs+haTVb8= x-microsoft-antispam: BCL:0;PCL:0;RULEID:(2390098)(7020095)(201702061078)(5061506573)(5061507331)(1603103135)(2017031320274)(2017031324274)(2017031323274)(201702181274)(2017031322404)(1603101475)(1601125500)(1701031045);SRVR:BL2NAM02HT134; x-ms-traffictypediagnostic: BL2NAM02HT134: x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(4566010)(82015058);SRVR:BL2NAM02HT134;BCL:0;PCL:0;RULEID:;SRVR:BL2NAM02HT134; x-microsoft-antispam-message-info: Fb2YewWFcKlZNFOQZRvWvA47Zcz+M+T2lGRQ0L+JAcWtQFvjj0zLL/R+i7V1xjgJ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: live.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: f12efbb0-867f-4c93-8261-502eceebfafa X-MS-Exchange-CrossTenant-Network-Message-Id: 00a68ce6-c8e3-4672-1741-08d65453e771 X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: f12efbb0-867f-4c93-8261-502eceebfafa X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Nov 2018 10:34:26.4603 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Internet X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2NAM02HT134 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org It`s possible ip overrun in lzo1x_1_do_compress() when compressed page is point to the end of memory and which virtual address is 0xfffffffffffff000. Leading to a NULL pointer access during the get_unaligned_le32(ip). Fix this panic: [ 2738.034508] Unable to handle kernel NULL pointer dereference at virtual = address 00000009 [ 2738.034515] Mem abort info: [ 2738.034518] Exception class =3D DABT (current EL), IL =3D 32 bits [ 2738.034520] SET =3D 0, FnV =3D 0 [ 2738.034523] EA =3D 0, S1PTW =3D 0 [ 2738.034524] FSC =3D 5 [ 2738.034526] Data abort info: [ 2738.034528] ISV =3D 0, ISS =3D 0x00000005 [ 2738.034530] CM =3D 0, WnR =3D 0 [ 2738.034533] user pgtable: 4k pages, 39-bit VAs, pgd =3D ffffffff94cee000 [ 2738.034535] [0000000000000009] *pgd=3D0000000000000000, *pud=3D000000000= 0000000 ... [ 2738.034592] pc : lzo1x_1_do_compress+0x198/0x610 [ 2738.034595] lr : lzo1x_1_compress+0x98/0x3d8 [ 2738.034597] sp : ffffff801caa3470 pstate : 00c00145 [ 2738.034598] x29: ffffff801caa3500 x28: 0000000000001000 [ 2738.034601] x27: 0000000000001000 x26: fffffffffffff000 [ 2738.034604] x25: ffffffff4ebc0000 x24: 0000000000000000 [ 2738.034607] x23: 000000000000004c x22: fffffffffffff7b8 [ 2738.034610] x21: ffffffff2e2ee0b3 x20: ffffffff2e2ee0bb [ 2738.034612] x19: 0000000000000fcc x18: fffffffffffff84a [ 2738.034615] x17: 00000000801b03d6 x16: 0000000000000782 [ 2738.034618] x15: ffffffff2e2ee0bf x14: fffffffffffffff0 [ 2738.034620] x13: 000000000000000f x12: 0000000000000020 [ 2738.034623] x11: 000000001824429d x10: ffffffffffffffec [ 2738.034626] x9 : 0000000000000009 x8 : 0000000000000000 [ 2738.034628] x7 : 0000000000000868 x6 : 0000000000000434 [ 2738.034631] x5 : ffffffff4ebc0000 x4 : 0000000000000000 [ 2738.034633] x3 : ffffff801caa3510 x2 : ffffffff2e2ee000 [ 2738.034636] x1 : 0000000000000000 x0 : fffffffffffff000 ... [ 2738.034717] Process kworker/u16:1 (pid: 8705, stack limit =3D 0xffffff80= 1caa0000) [ 2738.034720] Call trace: [ 2738.034722] lzo1x_1_do_compress+0x198/0x610 [ 2738.034725] lzo_compress+0x48/0x88 [ 2738.034729] crypto_compress+0x14/0x20 [ 2738.034733] zcomp_compress+0x2c/0x38 [ 2738.034736] zram_bvec_rw+0x3d0/0x860 [ 2738.034738] zram_rw_page+0x88/0xe0 [ 2738.034742] bdev_write_page+0x70/0xc0 [ 2738.034745] __swap_writepage+0x58/0x3f8 [ 2738.034747] swap_writepage+0x40/0x50 [ 2738.034750] shrink_page_list+0x4fc/0xe58 [ 2738.034753] reclaim_pages_from_list+0xa0/0x150 [ 2738.034756] reclaim_pte_range+0x18c/0x1f8 [ 2738.034759] __walk_page_range+0xf8/0x1e0 [ 2738.034762] walk_page_range+0xf8/0x130 [ 2738.034765] reclaim_task_anon+0xcc/0x168 [ 2738.034767] swap_fn+0x438/0x668 [ 2738.034771] process_one_work+0x1fc/0x460 [ 2738.034773] worker_thread+0x2d0/0x478 [ 2738.034775] kthread+0x110/0x120 [ 2738.034778] ret_from_fork+0x10/0x18 [ 2738.034781] Code: 3800167f 54ffffa8 d100066f 14000031 (b9400131) [ 2738.034784] ---[ end trace 9b5cca106f0e54d1 ]--- [ 2738.035473] Kernel panic - not syncing: Fatal exception crash> dis lzo1x_1_do_compress+100 3 -l ../kernel/msm-4.14/lib/lzo/lzo1x_compress.c: 44 0xffffff8dec8c6af4 : cmp x9, x10 0xffffff8dec8c6af8 : b.cc 0xffffff8dec8c6c28 0xffffff8dec8c6afc : b 0xffffff8dec8c7094 crash> dis lzo1x_1_do_compress+0x198 0xffffff8dec8c6c28 : ldr w17, [x9] ip =3D x9 =3D 0x0000000000000009 is overflow. Signed-off-by: liyueyi --- lib/lzo/lzo1x_compress.c | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/lib/lzo/lzo1x_compress.c b/lib/lzo/lzo1x_compress.c index 236eb21..a0265a6 100644 --- a/lib/lzo/lzo1x_compress.c +++ b/lib/lzo/lzo1x_compress.c @@ -17,6 +17,9 @@ #include #include "lzodefs.h" =20 +#define OVERFLOW_ADD_CHECK(a, b) \ + ((size_t)~0 - (size_t)(a) < (size_t)(b) ? true : false) + static noinline size_t lzo1x_1_do_compress(const unsigned char *in, size_t in_len, unsigned char *out, size_t *out_len, @@ -39,6 +42,8 @@ lzo1x_1_do_compress(const unsigned char *in, size_t in_le= n, size_t t, m_len, m_off; u32 dv; literal: + if (unlikely(OVERFLOW_ADD_CHECK(ip, 1 + ((ip - ii) >> 5)))) + break; ip +=3D 1 + ((ip - ii) >> 5); next: if (unlikely(ip >=3D ip_end)) @@ -99,7 +104,8 @@ lzo1x_1_do_compress(const unsigned char *in, size_t in_l= en, m_len +=3D 8; v =3D get_unaligned((const u64 *) (ip + m_len)) ^ get_unaligned((const u64 *) (m_pos + m_len)); - if (unlikely(ip + m_len >=3D ip_end)) + if (unlikely(OVERFLOW_ADD_CHECK(ip, m_len) + || (ip + m_len >=3D ip_end))) goto m_len_done; } while (v =3D=3D 0); } @@ -124,7 +130,8 @@ lzo1x_1_do_compress(const unsigned char *in, size_t in_= len, m_len +=3D 4; v =3D get_unaligned((const u32 *) (ip + m_len)) ^ get_unaligned((const u32 *) (m_pos + m_len)); - if (unlikely(ip + m_len >=3D ip_end)) + if (unlikely(OVERFLOW_ADD_CHECK(ip, m_len) + || (ip + m_len >=3D ip_end))) goto m_len_done; } while (v =3D=3D 0); } @@ -160,7 +167,8 @@ lzo1x_1_do_compress(const unsigned char *in, size_t in_= len, if (ip[m_len] !=3D m_pos[m_len]) break; m_len +=3D 1; - if (unlikely(ip + m_len >=3D ip_end)) + if (unlikely(OVERFLOW_ADD_CHECK(ip, m_len) + || (ip + m_len >=3D ip_end))) goto m_len_done; } while (ip[m_len] =3D=3D m_pos[m_len]); } --=20 2.7.4