Re: stack out-of-bounds write in mce-inject.c

From: Dmitry Vyukov
Date: Fri Apr 27 2018 - 12:07:01 EST


On Fri, Apr 27, 2018 at 5:41 PM, Borislav Petkov <bp@xxxxxxxxx> wrote:
> On Fri, Apr 27, 2018 at 05:24:24PM +0200, Dmitry Vyukov wrote:
>> Hi,
>>
>> Opening /sys/kernel/debug/mce-inject/flags overwrites stack:
>>
>> ==================================================================
>> BUG: KASAN: stack-out-of-bounds in vsnprintf+0x1b23/0x1b40 lib/vsprintf.c:2365
>> Write of size 1 at addr ffff8800627b7abb by task egrep/4309
>
> How do you trigger this exactly?
>
> You grep it for something apparently...


find /sys -exec grep "64" {} \; -print