Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp597210yba; Wed, 24 Apr 2019 06:38:12 -0700 (PDT) X-Google-Smtp-Source: APXvYqz9Ev2QRObRR/MLqbioSwZtFivwddluWKiwIW8Kqhv9kCgFcOiSiI48IoCQHqUygSc5sWwB X-Received: by 2002:aa7:8694:: with SMTP id d20mr32941461pfo.81.1556113092731; Wed, 24 Apr 2019 06:38:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1556113092; cv=none; d=google.com; s=arc-20160816; b=uUR9RV+ftd0VJUssEXvt/OJzbUytdRBEbg25UmUfR5BWuHf0+jFSasaQ38REXcfMmN v7jfgleKk0eU672JFJ+7IBrJLBgqy0D2+epPqxOcb/5PWUuOGiauE+Hb8cEJoVgO9JO+ yd99tTyboMGLyAc+5fwRuJZIQq46Fw4Ds8nB7IUgpgYqzWKHmouaSuP2O49iaQTfjd1F 05CTDDydqSON06ADeGTc3DFFGntleVY2G0V4J2dzuCRWYkG4LaxKsY+p5LGxnAq+7xqz i5tD0upBmh4rBNJUm5x/Y/DuBfbU3RNcLDNuquB6Pz2nGGPfyy8V6jxN2McOvZwapoh0 HBXg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:date:subject:cc:to:from :dkim-signature; bh=ETa+dFWNCZnNxwVqcCbdkTQv/b5T4kuYZin0xotChMQ=; b=d6XKIEiSxG+suH2Rbt1SvKxFs3lbvGv3Qd7wQakdaBRF1u99Epw4Xs5pb59ZpWJzmV 0DNs+xsZPzXlIdFIp2yRA+gb6TLsAqjmhY1Fb/tT9kIZlOh4rVfsg1o6HKnSDThL0kM+ j2b7SNf5ynZWU2Yww5dnuExyvZnqvtzBlY43EKmTAvzHN6y4ZUpv3l4Aww31kS7DTv+D Bg2VAORfgtH+ydt1UbupDlaNrGRmIPqFJCtpWLlSEABhPpZFrvjP+UaFWFCU239XTKTj phog7GIWRU9yALLUngpAvw2/v304PMLHNoBLnvpJmB9KUSKbP3XrqlZNtEHey5QfEZhf vBIA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=qhZXQcYk; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g34si18923455pld.115.2019.04.24.06.37.55; Wed, 24 Apr 2019 06:38:12 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=qhZXQcYk; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729918AbfDXKWk (ORCPT + 99 others); Wed, 24 Apr 2019 06:22:40 -0400 Received: from mail-pl1-f196.google.com ([209.85.214.196]:44747 "EHLO mail-pl1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727277AbfDXKVT (ORCPT ); Wed, 24 Apr 2019 06:21:19 -0400 Received: by mail-pl1-f196.google.com with SMTP id y12so6499327plk.11 for ; Wed, 24 Apr 2019 03:21:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=ETa+dFWNCZnNxwVqcCbdkTQv/b5T4kuYZin0xotChMQ=; b=qhZXQcYkMNsv8xuOtmo9utP8unEhA51+NsHInSOsCQIazmTUFnYncd5lPryfHab8w9 fCBuUGfXB57kWC3kySqpZWWkGp5RJz5CWTRcxzBEYP37PuavbPv6gbhFvtFirshJompx mw9PcYQQWppU5X7dI5dpi91yEL1+8MaYaUHJQoh5pZX/qJdb1FYjYlvKRcgUPH6IL6qh DSwMzQXRsN42SKxSktXIuiAZtXONFAB4Q2CdwVcsQUn0g/KSqKJi0jAFfmwVCNaazUf8 r/IZyRsPjcsXckYHXuplKMk8WhKRSzy0daCrRsGFliaMqkNlu8Chlv46HTwq41JoUj0k FVaw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=ETa+dFWNCZnNxwVqcCbdkTQv/b5T4kuYZin0xotChMQ=; b=I7zvHA+cv4030PDnvYUw6C08YMyq+v7LLkeCpke3fYrk3xFWDo2NuHBlWbYfuMrqiI O49dcGl9G/4IwWXWBVX0bGLbBd7kk3i4YC46kHMw2lzJzk+xWSDVhEsuJfzqYtAbRwKS 7bC3M5Gz7RIgDLuiMy1ejFtSCPVmm1ajen53e1rIFMKEB7yX3UeoIJ6qhhqRSG/m4Dxp TRaa9POUGDguvahF3Fsu0cMItOTG+2X7bgEmk+UKDsJyCrKvoxof+Sm7LPZn5hVqXU9h ygjxuF2U1Y1SfYzuO5PCgMTQGqnft91WWNljE+7THvsTpxhCM/reZLETTkfaCVXksCUn Ytpw== X-Gm-Message-State: APjAAAWvERL5PDHgGHsKhit4sem8j/+HlMX/XWvpLlxYNyY0keccCH9O 9hQzs5YemMdN6lSlNBKQUV8= X-Received: by 2002:a17:902:2ba6:: with SMTP id l35mr27019443plb.56.1556101278435; Wed, 24 Apr 2019 03:21:18 -0700 (PDT) Received: from localhost.localdomain (ch.ptr162.ptrcloud.net. [153.122.97.60]) by smtp.gmail.com with ESMTPSA id k9sm23310185pga.22.2019.04.24.03.21.13 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 24 Apr 2019 03:21:17 -0700 (PDT) From: Weikang shi To: keescook@chromium.org Cc: arnd@arndb.de, gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org, swkhack Subject: [PATCH] lkdtm: fix potential use after free Date: Wed, 24 Apr 2019 18:21:03 +0800 Message-Id: <20190424102103.11816-1-swkhack@gmail.com> X-Mailer: git-send-email 2.17.1 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: swkhack The function lkdtm_WRITE_AFTER_FREE calls kfree(base) to free the memory of base. However, following kfree(base), it write the memory which base point to via base[offset] = 0x0abcdef0. This may result in a use-after-free bug. This patch moves kfree(base) after the write. Signed-off-by: swkhack --- drivers/misc/lkdtm/heap.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/misc/lkdtm/heap.c b/drivers/misc/lkdtm/heap.c index 65026d7de..0b9141525 100644 --- a/drivers/misc/lkdtm/heap.c +++ b/drivers/misc/lkdtm/heap.c @@ -40,8 +40,8 @@ void lkdtm_WRITE_AFTER_FREE(void) pr_info("Allocated memory %p-%p\n", base, &base[offset * 2]); pr_info("Attempting bad write to freed memory at %p\n", &base[offset]); - kfree(base); base[offset] = 0x0abcdef0; + kfree(base); /* Attempt to notice the overwrite. */ again = kmalloc(len, GFP_KERNEL); kfree(again); -- 2.17.1