lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 23 Jun 2014 10:38:57 +0100 From: Markos Chandras <markos.chandras@...tec.com> To: <linux-mips@...ux-mips.org> CC: Markos Chandras <markos.chandras@...tec.com>, "David S. Miller" <davem@...emloft.net>, Daniel Borkmann <dborkman@...hat.com>, "Alexei Starovoitov" <ast@...mgrid.com>, <netdev@...r.kernel.org> Subject: [PATCH 14/17] MIPS: bpf: Prevent kernel fall over for >=32bit shifts Remove BUG_ON() if the shift immediate is >=32 to avoid kernel crashes due to malicious user input. Since the micro-assembler will not allow an immediate greater or equal to 32, we will use the maximum value which is 31. This will do the correct thing on either 32- or 64-bit cores since no 64-bit instructions are being used in JIT. Cc: "David S. Miller" <davem@...emloft.net> Cc: Daniel Borkmann <dborkman@...hat.com> Cc: Alexei Starovoitov <ast@...mgrid.com> Cc: netdev@...r.kernel.org Signed-off-by: Markos Chandras <markos.chandras@...tec.com> --- arch/mips/net/bpf_jit.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/arch/mips/net/bpf_jit.c b/arch/mips/net/bpf_jit.c index 1bcd599d9971..09ebc886c7aa 100644 --- a/arch/mips/net/bpf_jit.c +++ b/arch/mips/net/bpf_jit.c @@ -309,7 +309,8 @@ static inline void emit_sll(unsigned int dst, unsigned int src, unsigned int sa, struct jit_ctx *ctx) { /* sa is 5-bits long */ - BUG_ON(sa >= BIT(5)); + if (sa >= BIT(5)) + sa = BIT(5) - 1; emit_instr(ctx, sll, dst, src, sa); } @@ -323,7 +324,8 @@ static inline void emit_srl(unsigned int dst, unsigned int src, unsigned int sa, struct jit_ctx *ctx) { /* sa is 5-bits long */ - BUG_ON(sa >= BIT(5)); + if (sa >= BIT(5)) + sa = BIT(5) - 1; emit_instr(ctx, srl, dst, src, sa); } -- 2.0.0 -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists