From patchwork Thu Mar 1 15:24:20 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Sasha Levin X-Patchwork-Id: 130250 Delivered-To: patch@linaro.org Received: by 10.80.172.228 with SMTP id x91csp2941517edc; Thu, 1 Mar 2018 07:30:22 -0800 (PST) X-Google-Smtp-Source: AG47ELuS3u+de/nBZFd0Crz7Lgq14yg1PFl2/T8NmTd3EAoAzwlOAgg17nZ2P+i/RtT3n4cnNhfy X-Received: by 2002:a17:902:b901:: with SMTP id bf1-v6mr2280102plb.175.1519918221895; Thu, 01 Mar 2018 07:30:21 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1519918221; cv=none; d=google.com; s=arc-20160816; b=UlLVw5wletVPgtgTlsfUb1/OZb02kAOlxMnmsO2qCtte94rcQe1G+LqQe69sUWW2rY CYa6FlKpsJqxxnRWrwEH1F+2Hl0l9R057pOReYIfM+ycNemwH1Htg60s1WvFrAYrlrvW K8021EvpR0j3v9SPCSqHoFWjU1V8Wek0KMRIdhN0FN8WhgFk7mn/OxRw38ZsjAiBOHME gerxAi0jGyH4jNnVRZ6Ouqcu+3bff5NkYo1MmHKHwt5bnGwIozatQq7QCJ00h7sDhEbD nq9l67Fdn8IGnaltRxIU9KOxMlmF97D1qNTdsW8cz1XDngK4yNN9YmeWgHhzlYS/OeF4 fRMg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=MAfyDZ8xPyq/YuGdMxuvS7q2F8ihtQ6ZPAhwyg6FmXU=; b=FQmQW4WUw55J+h9Qh5XMunXCAG1VmXFeJ/Svm3IqdaYkhL24vdpaVOc/gt6QUpmdya K0esSWCzWciFNBuY3AK552DXEkAyOv7Ky0r9KDnmUxm3ddqTLbSJJekCra21Wj5i+d2R QMrDdzPBl4N7h/w5xzCbayy9r0fFse/kBOVmXu1+rub4txaLRSx0SjTJGL0sFajvv25e pCzNi430NdW72JVE3OLZoH0JuJQVG7EHHvIH57lc5qGOGuIX35R7VTbrMVm6O8Gg7YZY /EIdRwIGVKMyA5u4W1ZkGq07xYT8m33XFMYLQzLekJ3hoX9akIhA0LR66VEV7EwkdqT4 HRvg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=aj9mlurZ; spf=pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id z7si2597209pgp.660.2018.03.01.07.30.21; Thu, 01 Mar 2018 07:30:21 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=aj9mlurZ; spf=pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1032011AbeCAPaT (ORCPT + 10 others); Thu, 1 Mar 2018 10:30:19 -0500 Received: from mail-sn1nam02on0109.outbound.protection.outlook.com ([104.47.36.109]:7623 "EHLO NAM02-SN1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1032212AbeCAPaP (ORCPT ); Thu, 1 Mar 2018 10:30:15 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=MAfyDZ8xPyq/YuGdMxuvS7q2F8ihtQ6ZPAhwyg6FmXU=; b=aj9mlurZ8SQMr0b1bL8h3AwGiwOvd2kySAF9BZDbveiDJqLa0RcQJCch4i6Oei5TcmqbjF/TkzLzQvN35IqHlzQNtM1fIU8dzp1ac3NbSmouNIcatm16USs5s3tgJ3x/uy8OBi/P1lDJMNiWHCoTJGLlHELm9agdzBM9EeB1cYo= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB0887.namprd21.prod.outlook.com (52.132.132.156) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.567.2; Thu, 1 Mar 2018 15:30:13 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8063:c68a:b210:7446]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8063:c68a:b210:7446%2]) with mapi id 15.20.0567.006; Thu, 1 Mar 2018 15:30:13 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "stable-commits@vger.kernel.org" CC: Li Jinyue , Thomas Gleixner , Sasha Levin Subject: [added to the 4.1 stable tree] futex: Prevent overflow by strengthen input validation Thread-Topic: [added to the 4.1 stable tree] futex: Prevent overflow by strengthen input validation Thread-Index: AQHTsXFe2EJ2UUr1lE+p1YfJfEjmLw== Date: Thu, 1 Mar 2018 15:24:20 +0000 Message-ID: <20180301152116.1486-181-alexander.levin@microsoft.com> References: <20180301152116.1486-1-alexander.levin@microsoft.com> In-Reply-To: <20180301152116.1486-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1; DM5PR2101MB0887; 6:trBk5plPUNB6IOzXmG06aqXM47t3hnr4COSZ0HqSdaB1/Owu8S1CSejRBVESySNzWU8r3F8lVmXcOMe7VkwlRBZb+QA/D0BmhbAP/edCPhsTWP53xdHNULiEBpK0pqwjMgpJ3CAvn8fVbQvWKKXqJN1DW0iVdmaQGetOabqdU/YQYPSkTap3GLjqjiAulrQoSXMjOT4vCCTNNBsPMXOqqSPYyD9PhxGWe+o/ARixoB8BEBN+biYQwzO6FBPfaw9SUq2mOWvlpcSaLyR3YDcC9mmX94YeKpSbFIA24Qlvmc2InbiS9M+MU/dUwOFsNaqeczpXEc2WoRAbyvS250bxmaTX8R88wPbB4vmwBthd4uqWD61YxbDjHQvM1enDL5kL; 5:fiRE2bXH4JKHY0eirY9s4J5zuspURV/tSuWmNJXNd2sYfQVHlOZupHZzneaAfNsV/1fxCAbwZdAs8Ia6ke3PfHDqLXIf5UWTZWn5iFUMwEfMUVD7hybqK4sr5N6415Gu8el7BGoNprubTcPfpOrn0JC7dNjF89Y0DpwOmS1t+Yk=; 24:XZmIZV/zXV0eidK7JwLbPWCW+u7w8uFJP3aZOIuM0bQsnIN1NxeksLb2TaQublaWoWaz3ilx848ZleGgbzfILJQKBXCDkYiDDYVva6F4W44=; 7:JGZTI9VyVNSu2ql6zbkezQFPUFVQ4cp6JkTSgyj4bxaC4SdaQvIj5VqNNIAhVb3L5Qn91RfMnyieSUTereUG9fJXz9CDp7Fid/C4QkuzOPixvUnyvnAR27Np2czZzDSkwfc8PEv34qJV7e+RCGrW4HqNn4iQhpcl9GMTZfZ8K4hpVN4YUcvHnub3vwWK86GXoBw48QlYO2mN6Ja+n9aJXHTIEr7Va24+6Hc+jBBahXPv80yb9O6Ums0WDlUVfFDj x-ms-office365-filtering-ht: Tenant x-ms-office365-filtering-correlation-id: a1edd766-dc1c-49bb-ce89-08d57f8953ff x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(4534165)(4627221)(201703031133081)(201702281549075)(48565401081)(5600026)(4604075)(3008032)(2017052603307)(7193020); SRVR:DM5PR2101MB0887; x-ms-traffictypediagnostic: DM5PR2101MB0887: x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(20558992708506)(89211679590171)(9452136761055)(50582790962513)(42068640409301); x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(61425038)(6040501)(2401047)(8121501046)(5005006)(10201501046)(93006095)(93001095)(3231220)(944501224)(52105095)(3002001)(6055026)(61426038)(61427038)(6041288)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123562045)(20161123558120)(20161123560045)(6072148)(201708071742011); SRVR:DM5PR2101MB0887; BCL:0; PCL:0; RULEID:; SRVR:DM5PR2101MB0887; x-forefront-prvs: 05986C03E0 x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(376002)(39380400002)(39860400002)(396003)(366004)(346002)(199004)(189003)(3280700002)(305945005)(7736002)(6116002)(3846002)(105586002)(97736004)(1076002)(6512007)(2906002)(2501003)(5250100002)(575784001)(76176011)(99286004)(25786009)(86612001)(81166006)(81156014)(6306002)(53936002)(8676002)(4326008)(86362001)(10290500003)(316002)(106356001)(14454004)(26005)(186003)(6346003)(54906003)(102836004)(6506007)(107886003)(2900100001)(110136005)(22452003)(6436002)(36756003)(6486002)(68736007)(478600001)(6666003)(66066001)(966005)(72206003)(5660300001)(8936002)(10090500001)(2950100002)(3660700001)(22906009); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR2101MB0887; H:DM5PR2101MB1032.namprd21.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-message-info: XSh+m1AYLLyPaLbhP65eGfuDUpmmixbjjxKOUd/NMNyPbgSdRDjovXhC27zHES3U/U/23daIYdyRs4OTxXb5RzPQkorWuKEvFtIdDKq3rDuKI1Gc+FlvN7GGeVH495vVE3N7X0fLL5UFjPuf493+nijMx0rTNpdiczNGVWOn38g= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: a1edd766-dc1c-49bb-ce89-08d57f8953ff X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Mar 2018 15:24:20.4439 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB0887 Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org From: Li Jinyue This patch has been added to the 4.1 stable tree. If you have any objections, please let us know. -- 2.14.1 =============== [ Upstream commit fbe0e839d1e22d88810f3ee3e2f1479be4c0aa4a ] UBSAN reports signed integer overflow in kernel/futex.c: UBSAN: Undefined behaviour in kernel/futex.c:2041:18 signed integer overflow: 0 - -2147483648 cannot be represented in type 'int' Add a sanity check to catch negative values of nr_wake and nr_requeue. Signed-off-by: Li Jinyue Signed-off-by: Thomas Gleixner Cc: peterz@infradead.org Cc: dvhart@infradead.org Cc: stable@vger.kernel.org Link: https://lkml.kernel.org/r/1513242294-31786-1-git-send-email-lijinyue@huawei.com Signed-off-by: Sasha Levin --- kernel/futex.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/kernel/futex.c b/kernel/futex.c index 959cc4fc6de5..4195616b27d9 100644 --- a/kernel/futex.c +++ b/kernel/futex.c @@ -1514,6 +1514,9 @@ static int futex_requeue(u32 __user *uaddr1, unsigned int flags, struct futex_hash_bucket *hb1, *hb2; struct futex_q *this, *next; + if (nr_wake < 0 || nr_requeue < 0) + return -EINVAL; + if (requeue_pi) { /* * Requeue PI only works on two distinct uaddrs. This