summaryrefslogtreecommitdiffstats
path: root/arch/mips/lib/iomap-pci.c
diff options
context:
space:
mode:
authorKees Cook <kees@kernel.org>2024-07-01 21:13:02 +0200
committerVlastimil Babka <vbabka@suse.cz>2024-07-03 12:24:20 +0200
commit734bbc1c97ea7e46e0e53b087de16c87c03bd65f (patch)
treea7c5cf2fb6c0215cfe298b79c26fecae47610a27 /arch/mips/lib/iomap-pci.c
parentmm/slab: Introduce kmem_buckets_create() and family (diff)
downloadlinux-734bbc1c97ea7e46e0e53b087de16c87c03bd65f.tar.xz
linux-734bbc1c97ea7e46e0e53b087de16c87c03bd65f.zip
ipc, msg: Use dedicated slab buckets for alloc_msg()
The msg subsystem is a common target for exploiting[1][2][3][4][5][6][7] use-after-free type confusion flaws in the kernel for both read and write primitives. Avoid having a user-controlled dynamically-size allocation share the global kmalloc cache by using a separate set of kmalloc buckets via the kmem_buckets API. Link: https://blog.hacktivesecurity.com/index.php/2022/06/13/linux-kernel-exploit-development-1day-case-study/ [1] Link: https://hardenedvault.net/blog/2022-11-13-msg_msg-recon-mitigation-ved/ [2] Link: https://www.willsroot.io/2021/08/corctf-2021-fire-of-salvation-writeup.html [3] Link: https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html [4] Link: https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html [5] Link: https://zplin.me/papers/ELOISE.pdf [6] Link: https://syst3mfailure.io/wall-of-perdition/ [7] Signed-off-by: Kees Cook <kees@kernel.org> Signed-off-by: Vlastimil Babka <vbabka@suse.cz>
Diffstat (limited to 'arch/mips/lib/iomap-pci.c')
0 files changed, 0 insertions, 0 deletions