Received: by 2002:a05:6359:c8b:b0:c7:702f:21d4 with SMTP id go11csp526815rwb; Mon, 26 Sep 2022 02:15:57 -0700 (PDT) X-Google-Smtp-Source: AMsMyM5pOk/iEEY6TvpCquMyO+aBqkJJho5UrGU4c5N2etGL9lbip6XgCV0TUnVUfWB9IvL06Oti X-Received: by 2002:a17:902:b7c3:b0:176:b7e6:ae6c with SMTP id v3-20020a170902b7c300b00176b7e6ae6cmr21242683plz.163.1664183757503; Mon, 26 Sep 2022 02:15:57 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1664183757; cv=none; d=google.com; s=arc-20160816; b=LCIv03CKbJugLxb3Egkleub45Qz6WvN36WYCEJ2Cw/8hkbeM0Obo+KqSqrDEgt7nQS yQqR5VGcBp4GwFqMj0TQKW4XombWKTutM/RVghwW6/9CQT8wIhdexZrnWBF16HJIKRHN yf13LNReKT4Kirrc+QkfBtiEl/AJXvEcJI6A+HzCJWcS9OKsiaCAlVIEVkvOZotLcJC1 1MzOuhL1YM7Ht7NYaARB8Hi1LbdbPkVP9oi0x+ei1OxEGGqLw1MznxGaSWsqFmRUTzTn T64j4s+SIhonH62JIQoOfHEdyWkK9UZV6oR3K4tnpfo6iuFNIzaZVnaRj9CRfNQuFY67 C6Qg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=u9Ueg6JqkUFsEs+9ZLeunmweARqCZFg8ijTZA/IqXFk=; b=FlI7/C0NFe4y5ve58U78Gb3Unvpbmo7760spuJBDYYd5wt7SOHiOFzg+pPkb7sd9z9 ThDt3pJUSUvq08JPPBX5obFq9/DBp2bFAbDs5urxLgyuGJH3CxxBYgLz5i+243jl8+P5 JrzIn8pYZYVGbVzmnfpb+E05HfK6ZkBmePLfOjRZMSU7ODw4CXb+cZVW0+g3dm0gEgF+ LXxI+9RoEERTCX7J9/XvAc+pJefaJfA7wUrbvk/J6Atzbk3XjefLK/8uOySm8Q/qiorN zF9cHT8n9YNTjzOqpu5TTGc1cIbDJoCFjQwCH8vXo7jB9Rn3yTn+Kmjn5pxU6ijsDiMx HE4A== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=p96oqW3A; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id j3-20020a17090276c300b001789bd4b752si10543215plt.178.2022.09.26.02.15.45; Mon, 26 Sep 2022 02:15:57 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=p96oqW3A; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234448AbiIZIhB (ORCPT + 99 others); Mon, 26 Sep 2022 04:37:01 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43736 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234440AbiIZIg7 (ORCPT ); Mon, 26 Sep 2022 04:36:59 -0400 Received: from ams.source.kernel.org (ams.source.kernel.org [IPv6:2604:1380:4601:e00::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 8B9AA26100 for ; Mon, 26 Sep 2022 01:36:58 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id 3E76DB819B2 for ; Mon, 26 Sep 2022 08:36:57 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8F881C433D6; Mon, 26 Sep 2022 08:36:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1664181415; bh=YSAoQJ22O4EPWE9D3y1mKWq5n0S3yyUIg/pnmSUmYvc=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=p96oqW3ADMU8mOx6NfyOW8Ouwx3e7if0mspOq2IqF6MhbtVKoUD0tQbFRlKvjJ72B FcT1CbiwhjcbDR0Tf/rpAxHD1wWkwqvW+bPA7zse9pcLCLiM3r9V/cAGJ444WBjns2 4FCJU1F6gpeqatXm7aaSDitBAwhnhya2bKU+YQZ0= Date: Mon, 26 Sep 2022 10:36:53 +0200 From: Greg KH To: Zheng Wang Cc: dimitri.sivanich@hpe.com, arnd@arndb.de, linux-kernel@vger.kernel.org, hackerzheng666@gmail.com, alex000young@gmail.com, security@kernel.org Subject: Re: [PATCH] misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault and gru_handle_user_call_os Message-ID: References: <20220926043618.566326-1-zyytlz.wz@163.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220926043618.566326-1-zyytlz.wz@163.com> X-Spam-Status: No, score=-7.2 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_HI, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Sep 26, 2022 at 12:36:18PM +0800, Zheng Wang wrote: > Gts may be freed in gru_check_chiplet_assignment. > The caller still use it after that, UAF happens. > > Fix it by introducing a return value to see if it's in error path or not. > Free the gts in caller if gru_check_chiplet_assignment check failed. > > Reported-by: Zheng Wang > > Signed-off-by: Zheng Wang > > --- > drivers/misc/sgi-gru/grufault.c | 14 ++++++++++++-- > drivers/misc/sgi-gru/grumain.c | 17 +++++++++++++---- > drivers/misc/sgi-gru/grutables.h | 2 +- > 3 files changed, 26 insertions(+), 7 deletions(-) > > diff --git a/drivers/misc/sgi-gru/grufault.c b/drivers/misc/sgi-gru/grufault.c > index d7ef61e602ed..2b5b049fbd38 100644 > --- a/drivers/misc/sgi-gru/grufault.c > +++ b/drivers/misc/sgi-gru/grufault.c > @@ -656,7 +656,9 @@ int gru_handle_user_call_os(unsigned long cb) > if (ucbnum >= gts->ts_cbr_au_count * GRU_CBR_AU_SIZE) > goto exit; > > - gru_check_context_placement(gts); > + ret = gru_check_context_placement(gts); > + if (ret) > + goto err; > > /* > * CCH may contain stale data if ts_force_cch_reload is set. > @@ -677,6 +679,10 @@ int gru_handle_user_call_os(unsigned long cb) > exit: > gru_unlock_gts(gts); > return ret; > +err: > + gru_unlock_gts(gts); > + gru_unload_context(gts, 1); > + return -EINVAL; > } > > /* > @@ -874,7 +880,7 @@ int gru_set_context_option(unsigned long arg) > } else { > gts->ts_user_blade_id = req.val1; > gts->ts_user_chiplet_id = req.val0; > - gru_check_context_placement(gts); > + ret = gru_check_context_placement(gts); > } > break; > case sco_gseg_owner: > @@ -889,6 +895,10 @@ int gru_set_context_option(unsigned long arg) > ret = -EINVAL; > } > gru_unlock_gts(gts); > + if (ret) { > + gru_unload_context(gts, 1); > + ret = -EINVAL; > + } > > return ret; > } > diff --git a/drivers/misc/sgi-gru/grumain.c b/drivers/misc/sgi-gru/grumain.c > index 9afda47efbf2..79903cf7e706 100644 > --- a/drivers/misc/sgi-gru/grumain.c > +++ b/drivers/misc/sgi-gru/grumain.c > @@ -716,9 +716,10 @@ static int gru_check_chiplet_assignment(struct gru_state *gru, > * chiplet. Misassignment can occur if the process migrates to a different > * blade or if the user changes the selected blade/chiplet. > */ > -void gru_check_context_placement(struct gru_thread_state *gts) > +int gru_check_context_placement(struct gru_thread_state *gts) > { > struct gru_state *gru; > + int ret = 0; > > /* > * If the current task is the context owner, verify that the > @@ -727,14 +728,16 @@ void gru_check_context_placement(struct gru_thread_state *gts) > */ > gru = gts->ts_gru; > if (!gru || gts->ts_tgid_owner != current->tgid) > - return; > + return ret; > > if (!gru_check_chiplet_assignment(gru, gts)) { > STAT(check_context_unload); > - gru_unload_context(gts, 1); > + ret = -EINVAL; > } else if (gru_retarget_intr(gts)) { > STAT(check_context_retarget_intr); > } > + > + return ret; > } > > > @@ -919,6 +922,7 @@ vm_fault_t gru_fault(struct vm_fault *vmf) > struct gru_thread_state *gts; > unsigned long paddr, vaddr; > unsigned long expires; > + int ret; > > vaddr = vmf->address; > gru_dbg(grudev, "vma %p, vaddr 0x%lx (0x%lx)\n", > @@ -934,7 +938,12 @@ vm_fault_t gru_fault(struct vm_fault *vmf) > mutex_lock(>s->ts_ctxlock); > preempt_disable(); > > - gru_check_context_placement(gts); > + ret = gru_check_context_placement(gts); > + if (ret) { > + mutex_unlock(>s->ts_ctxlock); > + gru_unload_context(gts, 1); > + return ret; > + } > > if (!gts->ts_gru) { > STAT(load_user_context); > diff --git a/drivers/misc/sgi-gru/grutables.h b/drivers/misc/sgi-gru/grutables.h > index 5efc869fe59a..f4a5a787685f 100644 > --- a/drivers/misc/sgi-gru/grutables.h > +++ b/drivers/misc/sgi-gru/grutables.h > @@ -632,7 +632,7 @@ extern int gru_user_flush_tlb(unsigned long arg); > extern int gru_user_unload_context(unsigned long arg); > extern int gru_get_exception_detail(unsigned long arg); > extern int gru_set_context_option(unsigned long address); > -extern void gru_check_context_placement(struct gru_thread_state *gts); > +extern int gru_check_context_placement(struct gru_thread_state *gts); > extern int gru_cpu_fault_map_id(void); > extern struct vm_area_struct *gru_find_vma(unsigned long vaddr); > extern void gru_flush_all_tlb(struct gru_state *gru); > -- > 2.25.1 > > Hi, This is the friendly patch-bot of Greg Kroah-Hartman. You have sent him a patch that has triggered this response. He used to manually respond to these common problems, but in order to save his sanity (he kept writing the same thing over and over, yet to different people), I was created. Hopefully you will not take offence and will fix the problem in your patch and resubmit it so that it can be accepted into the Linux kernel tree. You are receiving this message because of the following common error(s) as indicated below: - This looks like a new version of a previously submitted patch, but you did not list below the --- line any changes from the previous version. Please read the section entitled "The canonical patch format" in the kernel file, Documentation/SubmittingPatches for what needs to be done here to properly describe this. If you wish to discuss this problem further, or you have questions about how to resolve this issue, please feel free to respond to this email and Greg will reply once he has dug out from the pending patches received from other developers. thanks, greg k-h's patch email bot