Files
tegra-linux-noble/include/linux
Heiko Carstens 96e02d1586 exec: fix use-after-free bug in setup_new_exec()
Setting the task name is done within setup_new_exec() by accessing
bprm->filename. However this happens after flush_old_exec().
This may result in a use after free bug, flush_old_exec() may
"complete" vfork_done, which will wake up the parent which in turn
may free the passed in filename.
To fix this add a new tcomm field in struct linux_binprm which
contains the now early generated task name until it is used.

Fixes this bug on s390:

  Unable to handle kernel pointer dereference at virtual kernel address 0000000039768000
  Process kworker/u:3 (pid: 245, task: 000000003a3dc840, ksp: 0000000039453818)
  Krnl PSW : 0704000180000000 0000000000282e94 (setup_new_exec+0xa0/0x374)
  Call Trace:
  ([<0000000000282e2c>] setup_new_exec+0x38/0x374)
   [<00000000002dd12e>] load_elf_binary+0x402/0x1bf4
   [<0000000000280a42>] search_binary_handler+0x38e/0x5bc
   [<0000000000282b6c>] do_execve_common+0x410/0x514
   [<0000000000282cb6>] do_execve+0x46/0x58
   [<00000000005bce58>] kernel_execve+0x28/0x70
   [<000000000014ba2e>] ____call_usermodehelper+0x102/0x140
   [<00000000005bc8da>] kernel_thread_starter+0x6/0xc
   [<00000000005bc8d4>] kernel_thread_starter+0x0/0xc
  Last Breaking-Event-Address:
   [<00000000002830f0>] setup_new_exec+0x2fc/0x374

  Kernel panic - not syncing: Fatal exception: panic_on_oops

Reported-by: Sebastian Ott <sebott@linux.vnet.ibm.com>
Signed-off-by: Heiko Carstens <heiko.carstens@de.ibm.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2012-02-06 15:15:20 -08:00
..
2011-03-31 11:26:23 -03:00
2012-01-22 15:08:43 -05:00
2011-12-13 15:30:49 -05:00
2012-01-24 15:41:51 +02:00
2008-02-06 10:41:02 -08:00
2008-07-01 11:28:06 +10:00
2009-06-17 00:36:36 -04:00
2011-07-22 08:25:37 -07:00
2010-11-23 20:14:46 +00:00
2011-11-02 16:07:03 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2011-07-20 20:47:43 -04:00
2009-09-08 17:42:50 -07:00
2008-12-03 22:12:38 -08:00
2005-04-16 15:20:36 -07:00
2011-10-26 15:43:25 -04:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2011-07-26 16:49:47 -07:00
2009-04-01 08:59:23 -07:00
2011-01-15 20:07:45 -05:00
2005-04-16 15:20:36 -07:00
2011-03-22 17:43:59 -07:00
2005-04-16 15:20:36 -07:00
2008-10-20 08:52:42 -07:00
2011-03-11 14:25:50 +00:00
2009-01-30 23:40:06 +05:30
2011-07-26 16:49:47 -07:00
2011-08-03 11:30:42 -04:00
2008-06-06 11:29:10 -07:00
2009-01-04 13:33:20 -08:00
2005-04-16 15:20:36 -07:00
2010-06-24 21:30:09 -07:00
2011-07-31 22:05:09 +02:00
2009-11-20 20:13:39 +01:00
2009-11-20 20:13:39 +01:00
2011-07-26 16:49:47 -07:00
2011-03-31 11:26:23 -03:00
2010-12-16 17:53:38 +01:00
2010-10-25 08:02:40 -07:00
2008-07-25 10:53:33 -07:00
2005-04-16 15:20:36 -07:00
2012-01-10 16:30:42 -08:00
2005-04-16 15:20:36 -07:00
2012-01-03 22:54:57 -05:00
2011-08-25 16:25:33 -07:00
2011-10-29 21:20:22 +02:00
2011-03-31 11:26:23 -03:00
2007-07-17 10:23:04 -07:00
2011-03-22 17:44:15 -07:00
2008-12-25 11:01:43 +11:00
2011-07-06 14:44:42 -07:00
2011-12-13 09:26:45 +00:00
2011-07-05 23:42:17 -07:00
2011-01-10 08:51:44 -08:00
2011-07-26 16:49:47 -07:00
2010-08-04 11:00:45 +02:00
2011-11-07 23:54:53 +01:00
2011-05-23 10:47:06 -05:00
2012-01-04 08:56:31 -06:00
2011-05-29 13:03:09 +01:00
2011-10-31 20:19:04 +00:00
2007-02-09 17:39:36 -05:00
2009-11-04 09:50:58 -08:00
2011-03-10 11:35:17 +01:00
2011-05-24 10:21:29 +02:00
2009-09-14 17:41:42 -07:00
2009-01-30 23:46:40 +05:30
2011-11-26 14:59:39 -05:00
2011-12-09 17:35:51 -08:00
2008-01-28 23:21:18 +01:00
2007-06-01 08:18:29 -07:00
2011-12-11 18:25:16 -05:00
2012-01-12 20:13:04 -08:00
2011-09-14 15:24:51 -04:00
2011-03-31 11:26:23 -03:00
2012-01-03 22:54:58 -05:00
2011-01-12 20:16:43 -05:00
2005-04-16 15:20:36 -07:00
2011-07-26 16:49:47 -07:00
2011-07-26 16:49:47 -07:00
2011-01-10 08:51:44 -08:00
2005-04-16 15:20:36 -07:00
2011-01-07 17:50:27 +11:00
2011-01-07 17:50:23 +11:00
2011-12-13 11:58:49 +01:00
2009-06-18 13:04:05 -07:00
2009-11-04 09:50:58 -08:00
2009-09-01 01:13:31 -07:00
2010-02-09 11:13:56 +01:00
2011-03-31 11:26:23 -03:00
2011-06-27 16:06:19 -07:00
2010-03-07 22:17:09 +01:00
2012-01-12 20:13:08 -08:00
2011-02-23 00:53:26 +00:00
2011-07-01 10:37:15 +02:00
2012-01-03 22:54:56 -05:00
2009-11-04 09:50:58 -08:00
2005-04-16 15:20:36 -07:00
2009-11-04 09:50:58 -08:00
2010-06-03 03:21:52 -07:00
2009-01-30 23:56:48 +05:30
2011-11-13 16:10:10 -05:00
2008-08-02 18:36:10 +01:00
2011-07-21 13:47:54 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2012-01-03 22:55:17 -05:00
2009-04-21 13:41:48 -07:00
2006-10-04 00:31:09 -07:00
2011-12-11 18:25:16 -05:00
2011-09-27 18:08:04 +02:00
2011-03-31 11:26:23 -03:00
2012-01-09 13:52:09 +01:00
2010-08-10 11:49:21 -07:00
2010-12-09 20:17:07 -08:00
2011-02-17 11:12:40 -08:00
2011-02-13 16:54:24 -08:00
2011-01-24 14:45:11 +10:30
2012-01-12 20:13:11 -08:00
2012-01-17 15:40:51 -08:00
2010-09-09 18:57:24 -07:00
2011-03-31 11:26:23 -03:00
2011-12-27 11:26:41 +02:00
2011-09-16 19:20:20 -04:00
2007-07-17 10:23:03 -07:00
2011-04-25 18:14:10 -07:00
2009-06-16 19:47:48 -07:00
2005-04-16 15:20:36 -07:00
2008-04-29 08:06:01 -07:00
2007-05-09 12:30:49 -07:00
2010-12-06 11:03:46 -08:00
2009-09-22 07:17:35 -07:00
2009-06-16 08:40:20 +02:00
2010-06-03 03:21:52 -07:00
2005-04-16 15:20:36 -07:00
2012-01-12 20:13:10 -08:00
2006-11-30 04:40:22 +01:00
2010-02-10 23:49:08 +09:00
2008-06-06 11:29:12 -07:00
2011-07-26 16:49:47 -07:00
2011-11-14 00:47:54 -05:00
2009-06-17 18:02:11 -07:00
2011-07-31 12:18:16 -04:00
2011-10-31 14:03:22 +01:00
2005-04-16 15:20:36 -07:00
2011-01-16 13:47:07 -05:00
2012-01-06 12:10:26 -08:00
2005-04-16 15:20:36 -07:00
2012-01-12 15:23:04 -08:00
2011-05-26 17:12:37 -07:00
2011-12-13 09:26:45 +00:00
2011-03-31 11:26:23 -03:00
2006-10-03 23:01:26 +02:00
2008-06-11 21:00:38 -07:00
2011-11-02 16:07:02 -07:00
2011-01-13 08:03:21 -08:00
2011-03-31 11:26:23 -03:00
2005-04-16 15:20:36 -07:00
2009-03-30 15:22:01 +02:00
2012-01-03 22:55:07 -05:00
2010-02-10 17:47:17 -08:00
2005-04-16 15:20:36 -07:00
2010-09-08 18:16:55 -07:00
2008-01-30 13:31:47 +01:00
2012-01-03 22:54:56 -05:00
2010-11-15 13:24:06 -05:00
2009-11-04 09:50:58 -08:00
2010-05-11 10:09:47 +02:00
2011-07-26 14:50:01 -07:00
2005-04-16 15:20:36 -07:00
2012-02-02 12:55:17 -08:00
2010-06-03 03:21:52 -07:00
2011-06-07 10:02:35 +02:00
2012-01-03 22:52:40 -05:00
2008-02-07 08:42:34 -08:00
2009-04-08 14:33:38 -07:00
2012-01-09 09:33:57 +09:00
2005-04-16 15:20:36 -07:00
2011-07-26 16:49:47 -07:00
2005-04-16 15:20:36 -07:00
2011-12-13 09:26:45 +00:00
2011-07-26 16:49:47 -07:00
2011-07-25 20:57:11 -07:00
2008-07-20 17:12:37 -07:00
2007-05-08 11:15:18 -07:00
2010-08-09 16:48:44 -04:00
2006-10-01 00:39:18 -07:00
2011-10-31 17:30:47 -07:00
2011-08-03 14:25:22 -10:00
2005-04-16 15:20:36 -07:00
2012-01-03 22:54:56 -05:00
2008-10-13 09:51:40 -07:00
2011-02-02 15:28:18 +01:00
2010-11-29 08:55:25 +11:00
2010-11-29 08:55:22 +11:00
2011-06-27 20:30:08 +02:00
2006-09-28 17:53:59 -07:00
2012-01-24 12:25:14 -08:00
2005-04-16 15:20:36 -07:00
2011-11-02 16:07:02 -07:00
2010-05-19 22:40:47 -04:00
2007-12-26 19:36:35 -08:00
2005-04-16 15:20:36 -07:00
2011-03-31 11:26:23 -03:00
2011-07-26 16:49:47 -07:00
2011-09-14 15:24:51 -04:00
2011-03-31 11:26:23 -03:00
2011-01-13 08:03:24 -08:00
2005-04-16 15:20:36 -07:00