From patchwork Tue Feb 28 13:17:59 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alexander Potapenko X-Patchwork-Id: 733515 X-Patchwork-Delegate: davem@davemloft.net Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 3vXfK72p2gz9s8D for ; Wed, 1 Mar 2017 00:18:19 +1100 (AEDT) Authentication-Results: ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=google.com header.i=@google.com header.b="QKAof9kK"; dkim-atps=neutral Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752583AbdB1NSI (ORCPT ); Tue, 28 Feb 2017 08:18:08 -0500 Received: from mail-wm0-f41.google.com ([74.125.82.41]:38052 "EHLO mail-wm0-f41.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752550AbdB1NSF (ORCPT ); Tue, 28 Feb 2017 08:18:05 -0500 Received: by mail-wm0-f41.google.com with SMTP id u199so11478050wmd.1 for ; Tue, 28 Feb 2017 05:18:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=52L9aVuTZrXdqHrUSbJ2PjFmtSFYNKYLsT1LlayI3sk=; b=QKAof9kKb3DRAZqu4MAVnxZzjV6ky7ASSwJBXRqt3ZpRZv5QBsYvRtKsQ9QgJY6ScO ZdTJkzC9srVDDJVWmwI1+MA7uKC3CZna/3WtT9GhZHH8hh9vFyhLgT3jhSXmzASusF+f l5pzjM/0h3S6jEt9KuPf1T8OJpOx91AyRomIOwI4zQl5y8/bk+9HGcRaqP5h6tkl4E7a 3soACZd1no5CKhCUDIzeJNDSeW4m/B6yakbc2+Sp3rqXKKHwokZWFvDp6WesmbvNVHkZ ppEyHdcNaluSsJlB6W+r2J2yRMtu83Ln9DIT/silzSaORM0FOn69LxHM8XLQrPDLodSd wNEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=52L9aVuTZrXdqHrUSbJ2PjFmtSFYNKYLsT1LlayI3sk=; b=eHZ54/BSW/EjYeSQRTM/zBLl7+JV04PpN0l+xYfU9F51EHZzXsCs60eEh1W99Hkq2d tdb7ROJ07BDXBrT168f54BPj4KN/PapS/eJEzdz4U0gWbduV3BNjSyCSlWSt8odfuEh3 ADir7hC6bLKMfG/c4Yz1ACk1I/9c71HfvIcLax88YGwa5k144yRPkyzvIDRRkI12WWaA Cerq47rgo8aFkRFAtHCfZHQ/fcOaHNnDb8bsf4gLOGhnaaan8fDEK7Hnvo0mrxNaDJ0/ 0OFKm7eaXDKZGLJ6qm8PMigsSTulfxscHeAo32ek3vOsE1KxXoEK8vABuJLl3weAI7hg QMEw== X-Gm-Message-State: AMke39l7tV+WxjO2Gn/Pa1Lbl7TCxDea8E/LLPY4bqu+m9vY/aSysg7gliPBpnn0NZLIe7hb X-Received: by 10.28.212.198 with SMTP id l189mr5740528wmg.39.1488287883128; Tue, 28 Feb 2017 05:18:03 -0800 (PST) Received: from glider0.muc.corp.google.com ([100.105.28.21]) by smtp.gmail.com with ESMTPSA id l45sm2322264wrc.14.2017.02.28.05.18.02 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Tue, 28 Feb 2017 05:18:02 -0800 (PST) From: Alexander Potapenko To: dvyukov@google.com, kcc@google.com, edumazet@google.com Cc: linux-kernel@vger.kernel.org, netdev@vger.kernel.org Subject: [PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt() Date: Tue, 28 Feb 2017 14:17:59 +0100 Message-Id: <20170228131759.110380-1-glider@google.com> X-Mailer: git-send-email 2.11.0.483.g087da7b7c-goog Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org KMSAN (KernelMemorySanitizer, a new error detection tool) reports use of uninitialized memory in packet_bind_spkt(): ================================================================== BUG: KMSAN: use of unitialized memory CPU: 0 PID: 1074 Comm: packet Not tainted 4.8.0-rc6+ #1891 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 0000000000000000 ffff88006b6dfc08 ffffffff82559ae8 ffff88006b6dfb48 ffffffff818a7c91 ffffffff85b9c870 0000000000000092 ffffffff85b9c550 0000000000000000 0000000000000092 00000000ec400911 0000000000000002 Call Trace: [< inline >] __dump_stack lib/dump_stack.c:15 [] dump_stack+0x238/0x290 lib/dump_stack.c:51 [] kmsan_report+0x276/0x2e0 mm/kmsan/kmsan.c:1003 [] __msan_warning+0x5b/0xb0 mm/kmsan/kmsan_instr.c:424 [< inline >] strlen lib/string.c:484 [] strlcpy+0x9d/0x200 lib/string.c:144 [] packet_bind_spkt+0x144/0x230 net/packet/af_packet.c:3132 [] SYSC_bind+0x40d/0x5f0 net/socket.c:1370 [] SyS_bind+0x82/0xa0 net/socket.c:1356 [] entry_SYSCALL_64_fastpath+0x13/0x8f arch/x86/entry/entry_64.o:? chained origin: 00000000eba00911 [] save_stack_trace+0x27/0x50 arch/x86/kernel/stacktrace.c:67 [< inline >] kmsan_save_stack_with_flags mm/kmsan/kmsan.c:322 [< inline >] kmsan_save_stack mm/kmsan/kmsan.c:334 [] kmsan_internal_chain_origin+0x118/0x1e0 mm/kmsan/kmsan.c:527 [] __msan_set_alloca_origin4+0xc3/0x130 mm/kmsan/kmsan_instr.c:380 [] SYSC_bind+0x129/0x5f0 net/socket.c:1356 [] SyS_bind+0x82/0xa0 net/socket.c:1356 [] entry_SYSCALL_64_fastpath+0x13/0x8f arch/x86/entry/entry_64.o:? origin description: ----address@SYSC_bind (origin=00000000eb400911) ================================================================== (the line numbers are relative to 4.8-rc6, but the bug persists upstream) , when I run the following program as root: ===================================== #include #include #include #include int main() { struct sockaddr addr; memset(&addr, 0xff, sizeof(addr)); addr.sa_family = AF_PACKET; int fd = socket(PF_PACKET, SOCK_PACKET, htons(ETH_P_ALL)); bind(fd, &addr, sizeof(addr)); return 0; } ===================================== This happens because addr.sa_data copied from the userspace is not zero-terminated, and copying it with strlcpy() in packet_bind_spkt() results in calling strlen() on the kernel copy of that non-terminated buffer. Signed-off-by: Alexander Potapenko --- net/packet/af_packet.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c index 2bd0d1949312..1e7992f3e0a8 100644 --- a/net/packet/af_packet.c +++ b/net/packet/af_packet.c @@ -3111,7 +3111,11 @@ static int packet_bind_spkt(struct socket *sock, struct sockaddr *uaddr, if (addr_len != sizeof(struct sockaddr)) return -EINVAL; - strlcpy(name, uaddr->sa_data, sizeof(name)); + /* uaddr->sa_data comes from the userspace, it's not guaranteed to be + * zero-terminated. + */ + name[14] = '\0'; + strncpy(name, uaddr->sa_data, sizeof(name)); return packet_do_bind(sk, name, 0, pkt_sk(sk)->num); }