[PATCH] Hardening memory maunipulation.

From: Shawn Chang
Date: Wed Apr 29 2015 - 11:39:57 EST


From: Shawn C <citypw@xxxxxxxxx>

Hi kernel maintainers,

It won't allow the address above the TASK_SIZE being mmap'ed( or mprotect'ed).
This patch is from PaX/Grsecurity.

Thanks for your review time!

Signed-off-by: Shawn C <citypw@xxxxxxxxx>
---
mm/madvise.c | 4 ++++
mm/mempolicy.c | 5 +++++
mm/mlock.c | 4 ++++
mm/mprotect.c | 5 +++++
4 files changed, 18 insertions(+)

diff --git a/mm/madvise.c b/mm/madvise.c
index d551475..3f5dd3d 100644
--- a/mm/madvise.c
+++ b/mm/madvise.c
@@ -484,6 +484,10 @@ SYSCALL_DEFINE3(madvise, unsigned long, start, size_t, len_in, int, behavior)
if (end < start)
return error;

+ /* We should never reach the kernel address space here */
+ if (end > TASK_SIZE)
+ return error;
+
error = 0;
if (end == start)
return error;
diff --git a/mm/mempolicy.c b/mm/mempolicy.c
index ede2629..56c2eed 100644
--- a/mm/mempolicy.c
+++ b/mm/mempolicy.c
@@ -1161,6 +1161,11 @@ static long do_mbind(unsigned long start, unsigned long len,

if (end < start)
return -EINVAL;
+
+ /* We should never reach the kernel address space here */
+ if (end > TASK_SIZE)
+ return -EINVAL;
+
if (end == start)
return 0;

diff --git a/mm/mlock.c b/mm/mlock.c
index 6fd2cf1..c7f6785 100644
--- a/mm/mlock.c
+++ b/mm/mlock.c
@@ -566,6 +566,10 @@ static int do_mlock(unsigned long start, size_t len, int on)
return -EINVAL;
if (end == start)
return 0;
+
+ if (end > TASK_SIZE)
+ return -EINVAL;
+
vma = find_vma(current->mm, start);
if (!vma || vma->vm_start > start)
return -ENOMEM;
diff --git a/mm/mprotect.c b/mm/mprotect.c
index 8858483..cd58a31 100644
--- a/mm/mprotect.c
+++ b/mm/mprotect.c
@@ -351,6 +351,11 @@ SYSCALL_DEFINE3(mprotect, unsigned long, start, size_t, len,
end = start + len;
if (end <= start)
return -ENOMEM;
+
+ /* We should never reach the kernel address space here */
+ if (end > TASK_SIZE)
+ return -EINVAL;
+
if (!arch_validate_prot(prot))
return -EINVAL;

--
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/