lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:   Mon, 10 Jan 2022 23:15:26 +0000
From:   "Matthew Wilcox (Oracle)" <>
To:     Kees Cook <>
Cc:     "Matthew Wilcox (Oracle)" <>,,
Subject: [PATCH 0/4] Assorted improvements to usercopy

The HARDENED_USERCOPY_PAGESPAN config option is hard to turn on because
much of the kernel uses non-compound high-order page allocations.
This patchset extracts the valuable parts of HARDENED_USERCOPY_PAGESPAN
and then removes the remainder.

 - Use get_vm_area_size() instead of ->size directly (Mark Hemment)
 - Rebase to current Linus (the slab merge changed a lot of code)
 - Add the fourth patch to remove HARDENED_USERCOPY_PAGESPAN
 - Remove a now-unused variable
 - Prevent a NULL pointer dereference when a vmalloc-range pointer
   doesn't have an associated allocation (me)
 - Report better offsets than "0" (Kees)

Matthew Wilcox (Oracle) (4):
  mm/usercopy: Check kmap addresses properly
  mm/usercopy: Detect vmalloc overruns
  mm/usercopy: Detect large folio overruns

 arch/x86/include/asm/highmem.h   |  1 +
 include/linux/highmem-internal.h | 10 ++++
 mm/usercopy.c                    | 97 +++++++++-----------------------
 security/Kconfig                 | 13 +----
 4 files changed, 39 insertions(+), 82 deletions(-)


Powered by blists - more mailing lists