[packages/kernel/LINUX_4_9] - up to 4.9.49; fix CVE-2017-14340: xfs: unprivileged user kernel oops, too
arekm
arekm at pld-linux.org
Wed Sep 13 11:32:57 CEST 2017
commit 7379240e5f01c47f57b5063c9ccc0ff704124df3
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Wed Sep 13 11:32:50 2017 +0200
- up to 4.9.49; fix CVE-2017-14340: xfs: unprivileged user kernel oops, too
kernel-small_fixes.patch | 66 ++++++++++++++++++++++++++++++++++++++++++++++++
kernel.spec | 4 +--
2 files changed, 68 insertions(+), 2 deletions(-)
---
diff --git a/kernel.spec b/kernel.spec
index ed9ff8c3..f0948849 100644
--- a/kernel.spec
+++ b/kernel.spec
@@ -73,7 +73,7 @@
%define rel 1
%define basever 4.9
-%define postver .47
+%define postver .49
# define this to '-%{basever}' for longterm branch
%define versuffix -%{basever}
@@ -125,7 +125,7 @@ Source0: https://www.kernel.org/pub/linux/kernel/v4.x/linux-%{basever}.tar.xz
# Source0-md5: 0a68ef3615c64bd5ee54a3320e46667d
%if "%{postver}" != ".0"
Patch0: https://www.kernel.org/pub/linux/kernel/v4.x/patch-%{version}.xz
-# Patch0-md5: b3c2f0a15f538597811e7389bd553f38
+# Patch0-md5: 034e10554bed9724f30f25adc020aecc
%endif
Source1: kernel.sysconfig
diff --git a/kernel-small_fixes.patch b/kernel-small_fixes.patch
index 319191ce..46c63695 100644
--- a/kernel-small_fixes.patch
+++ b/kernel-small_fixes.patch
@@ -61,3 +61,69 @@ index 098ce9b179ee..fcf8d0aa66ec 100644
--
2.11.0
+commit b31ff3cdf540110da4572e3e29bd172087af65cc
+Author: Richard Wareing <rwareing at fb.com>
+Date: Wed Sep 13 09:09:35 2017 +1000
+
+ xfs: XFS_IS_REALTIME_INODE() should be false if no rt device present
+
+ If using a kernel with CONFIG_XFS_RT=y and we set the RHINHERIT flag on
+ a directory in a filesystem that does not have a realtime device and
+ create a new file in that directory, it gets marked as a real time file.
+ When data is written and a fsync is issued, the filesystem attempts to
+ flush a non-existent rt device during the fsync process.
+
+ This results in a crash dereferencing a null buftarg pointer in
+ xfs_blkdev_issue_flush():
+
+ BUG: unable to handle kernel NULL pointer dereference at 0000000000000008
+ IP: xfs_blkdev_issue_flush+0xd/0x20
+ .....
+ Call Trace:
+ xfs_file_fsync+0x188/0x1c0
+ vfs_fsync_range+0x3b/0xa0
+ do_fsync+0x3d/0x70
+ SyS_fsync+0x10/0x20
+ do_syscall_64+0x4d/0xb0
+ entry_SYSCALL64_slow_path+0x25/0x25
+
+ Setting RT inode flags does not require special privileges so any
+ unprivileged user can cause this oops to occur. To reproduce, confirm
+ kernel is compiled with CONFIG_XFS_RT=y and run:
+
+ # mkfs.xfs -f /dev/pmem0
+ # mount /dev/pmem0 /mnt/test
+ # mkdir /mnt/test/foo
+ # xfs_io -c 'chattr +t' /mnt/test/foo
+ # xfs_io -f -c 'pwrite 0 5m' -c fsync /mnt/test/foo/bar
+
+ Or just run xfstests with MKFS_OPTIONS="-d rtinherit=1" and wait.
+
+ Kernels built with CONFIG_XFS_RT=n are not exposed to this bug.
+
+ Fixes: f538d4da8d52 ("[XFS] write barrier support")
+ Cc: <stable at vger.kernel.org>
+ Signed-off-by: Richard Wareing <rwareing at fb.com>
+ Signed-off-by: Dave Chinner <david at fromorbit.com>
+ Signed-off-by: Linus Torvalds <torvalds at linux-foundation.org>
+
+diff --git a/fs/xfs/xfs_linux.h b/fs/xfs/xfs_linux.h
+index 9301c5a6060b..dcd1292664b3 100644
+--- a/fs/xfs/xfs_linux.h
++++ b/fs/xfs/xfs_linux.h
+@@ -270,7 +270,14 @@ static inline uint64_t howmany_64(uint64_t x, uint32_t y)
+ #endif /* DEBUG */
+
+ #ifdef CONFIG_XFS_RT
+-#define XFS_IS_REALTIME_INODE(ip) ((ip)->i_d.di_flags & XFS_DIFLAG_REALTIME)
++
++/*
++ * make sure we ignore the inode flag if the filesystem doesn't have a
++ * configured realtime device.
++ */
++#define XFS_IS_REALTIME_INODE(ip) \
++ (((ip)->i_d.di_flags & XFS_DIFLAG_REALTIME) && \
++ (ip)->i_mount->m_rtdev_targp)
+ #else
+ #define XFS_IS_REALTIME_INODE(ip) (0)
+ #endif
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/kernel.git/commitdiff/7379240e5f01c47f57b5063c9ccc0ff704124df3
More information about the pld-cvs-commit
mailing list