Received: by 2002:a05:6a10:a0d1:0:0:0:0 with SMTP id j17csp1799495pxa; Thu, 6 Aug 2020 16:41:53 -0700 (PDT) X-Google-Smtp-Source: ABdhPJww6N7a1DUwIPaEeh4yGYen5MKMFw/0lm8o3IGu8gFEpluPAK9Qn81ufx+bf29d0DklpINP X-Received: by 2002:a17:906:fb04:: with SMTP id lz4mr7009738ejb.394.1596757313070; Thu, 06 Aug 2020 16:41:53 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1596757313; cv=none; d=google.com; s=arc-20160816; b=YVl4fDeDWwStaPmALlETzbcGq9tjf0fB03y1s2CHTFXiEZZq454LDjMGUanBwA92Ua af7Y37CeR4/Nr3X+LmusT4mwj5nPT4hJSm+gh4x6dgI3t7d1noyIyIt+dsm3ROSFm9nm 4t1bYOLR+t7dxh6zwuR5rFKXpn5zbTSmQrdr7lBAspBCIdEjz6dN+j/8KcV3o2v8ks1o VyWxfYTo878p+NmFjYzLJ1gpqhTP67hd+8G+hGU8Vfk1hzPLxTkOXNmZ1xCTZ/bXwMgS MBpTMX/rx0NO8ImLcliZo8ZTU7LTRDsh4s5o3XV93/DALzWTdXqRfgh1j0kaeFcWYvJf Fblg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :robot-unsubscribe:robot-id:message-id:mime-version:references :in-reply-to:cc:subject:to:reply-to:from:dkim-signature :dkim-signature:date; bh=zDxatrwO+co72myHzmJiVqhEcOcAAOjarE+tDUP3zz0=; b=0px9QfqRAqyC8ulmojIBsJc3eCJtfuzefGtmxL3bFoUH9vNUO9/FteZjULDyGNxIqp 1F7c+CaSu9XD4PaC+9/Sm/mHxahq+/HFInNOT4EtFlWePiAaCkS9wv3XuwJFz1iTQg3Y 1SbO+L9EN9VmwUpq6beT8WnDBAJwZdGQ1BSy3salceNXRuTkR2zwm69sT+lMQtxr8ova 7LdvMpWP0GrHbfslQs99OoMrtn/rcgiDr9aZCYE10BUqIR2xTrRo7n7D7aCJoirtLir4 opMRVW9g29MPDsk0nJUQgcNMkS+vsgvkWYoLnHyHnnBM6eoKYLWWciPK4dpEGFdFJyLa Xq3g== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@linutronix.de header.s=2020 header.b=rzKES9e0; dkim=neutral (no key) header.i=@vger.kernel.org header.s=2020e header.b=vIRQpDGm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=linutronix.de Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id w6si4268127ejb.150.2020.08.06.16.41.30; Thu, 06 Aug 2020 16:41:53 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=fail header.i=@linutronix.de header.s=2020 header.b=rzKES9e0; dkim=neutral (no key) header.i=@vger.kernel.org header.s=2020e header.b=vIRQpDGm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=linutronix.de Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727120AbgHFXkT (ORCPT + 99 others); Thu, 6 Aug 2020 19:40:19 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49972 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726533AbgHFXiw (ORCPT ); Thu, 6 Aug 2020 19:38:52 -0400 Received: from galois.linutronix.de (Galois.linutronix.de [IPv6:2a0a:51c0:0:12e:550::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 71C43C061575; Thu, 6 Aug 2020 16:38:52 -0700 (PDT) Date: Thu, 06 Aug 2020 23:38:50 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1596757131; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zDxatrwO+co72myHzmJiVqhEcOcAAOjarE+tDUP3zz0=; b=rzKES9e0H1m5Nm6KXCA6vSDrWrdNJHMtiDPI/5LrnNgOggaF7wIoh74AoT5B65rK1j2YGa WHML9va4Uu+gWnMSVKQSemYzFa9DmsWSuXfeIdfvNYPcT122SI5D2DITvh61kWHpvk8+VB kvB4/+ZqejjuokyUC1/pZSHXKhTQMRL3xiIjjxlzLT7EJriZ5DJENYnfsoiRuIUQkwj0fB qSetmEqbttvWzhy5TE/upOJw2p1A6h4FxiO95Blhko0lod27CPwli9r/qlEd1flr+Iux6n avwM0yk2cMntgUxwUSQdYX7qrXD8Q6IVhpl5gsQtfZcB6xzUXxdUozKEXNrOOQ== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1596757131; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zDxatrwO+co72myHzmJiVqhEcOcAAOjarE+tDUP3zz0=; b=vIRQpDGmT0wZfMPayECEODhFEAxr/x4RCFzpOqM21Kk/qNBIy57BEcRnpyuxfs2VMBTLUt S4+3ucjKHYtSk3CQ== From: "tip-bot2 for Arvind Sankar" Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: x86/kaslr] x86/kaslr: Add a check that the random address is in range Cc: Arvind Sankar , Ingo Molnar , x86 , LKML In-Reply-To: <20200728225722.67457-22-nivedita@alum.mit.edu> References: <20200728225722.67457-22-nivedita@alum.mit.edu> MIME-Version: 1.0 Message-ID: <159675713045.3192.895736711102672509.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The following commit has been merged into the x86/kaslr branch of tip: Commit-ID: f49236ae424d499d02ee3ce35fb9130ddf95b03f Gitweb: https://git.kernel.org/tip/f49236ae424d499d02ee3ce35fb9130ddf95b03f Author: Arvind Sankar AuthorDate: Tue, 28 Jul 2020 18:57:22 -04:00 Committer: Ingo Molnar CommitterDate: Fri, 31 Jul 2020 11:08:17 +02:00 x86/kaslr: Add a check that the random address is in range Check in find_random_phys_addr() that the chosen address is inside the range that was required. Signed-off-by: Arvind Sankar Signed-off-by: Ingo Molnar Link: https://lore.kernel.org/r/20200728225722.67457-22-nivedita@alum.mit.edu --- arch/x86/boot/compressed/kaslr.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/arch/x86/boot/compressed/kaslr.c b/arch/x86/boot/compressed/kaslr.c index 80cdd20..735fcb2 100644 --- a/arch/x86/boot/compressed/kaslr.c +++ b/arch/x86/boot/compressed/kaslr.c @@ -803,6 +803,8 @@ static void process_e820_entries(unsigned long minimum, static unsigned long find_random_phys_addr(unsigned long minimum, unsigned long image_size) { + u64 phys_addr; + /* Bail out early if it's impossible to succeed. */ if (minimum + image_size > mem_limit) return 0; @@ -816,7 +818,15 @@ static unsigned long find_random_phys_addr(unsigned long minimum, if (!process_efi_entries(minimum, image_size)) process_e820_entries(minimum, image_size); - return slots_fetch_random(); + phys_addr = slots_fetch_random(); + + /* Perform a final check to make sure the address is in range. */ + if (phys_addr < minimum || phys_addr + image_size > mem_limit) { + warn("Invalid physical address chosen!\n"); + return 0; + } + + return (unsigned long)phys_addr; } static unsigned long find_random_virt_addr(unsigned long minimum,