Skip to content

Commit 9ea8d8b

Browse files
riteshharjanigregkh
authored andcommitted
powerpc/mm/fault: Fix kfence page fault reporting
[ Upstream commit 06dbbb4 ] copy_from_kernel_nofault() can be called when doing read of /proc/kcore. /proc/kcore can have some unmapped kfence objects which when read via copy_from_kernel_nofault() can cause page faults. Since *_nofault() functions define their own fixup table for handling fault, use that instead of asking kfence to handle such faults. Hence we search the exception tables for the nip which generated the fault. If there is an entry then we let the fixup table handler handle the page fault by returning an error from within ___do_page_fault(). This can be easily triggered if someone tries to do dd from /proc/kcore. eg. dd if=/proc/kcore of=/dev/null bs=1M Some example false negatives: =============================== BUG: KFENCE: invalid read in copy_from_kernel_nofault+0x9c/0x1a0 Invalid read at 0xc0000000fdff0000: copy_from_kernel_nofault+0x9c/0x1a0 0xc00000000665f950 read_kcore_iter+0x57c/0xa04 proc_reg_read_iter+0xe4/0x16c vfs_read+0x320/0x3ec ksys_read+0x90/0x154 system_call_exception+0x120/0x310 system_call_vectored_common+0x15c/0x2ec BUG: KFENCE: use-after-free read in copy_from_kernel_nofault+0x9c/0x1a0 Use-after-free read at 0xc0000000fe050000 (in kfence-#2): copy_from_kernel_nofault+0x9c/0x1a0 0xc00000000665f950 read_kcore_iter+0x57c/0xa04 proc_reg_read_iter+0xe4/0x16c vfs_read+0x320/0x3ec ksys_read+0x90/0x154 system_call_exception+0x120/0x310 system_call_vectored_common+0x15c/0x2ec Fixes: 90cbac0 ("powerpc: Enable KFENCE for PPC32") Suggested-by: Christophe Leroy <[email protected]> Reported-by: Disha Goel <[email protected]> Signed-off-by: Ritesh Harjani (IBM) <[email protected]> Reviewed-by: Christophe Leroy <[email protected]> Signed-off-by: Michael Ellerman <[email protected]> Link: https://patch.msgid.link/a411788081d50e3b136c6270471e35aba3dfafa3.1729271995.git.ritesh.list@gmail.com Signed-off-by: Sasha Levin <[email protected]>
1 parent f129087 commit 9ea8d8b

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

arch/powerpc/mm/fault.c

+8-2
Original file line numberDiff line numberDiff line change
@@ -431,10 +431,16 @@ static int ___do_page_fault(struct pt_regs *regs, unsigned long address,
431431
/*
432432
* The kernel should never take an execute fault nor should it
433433
* take a page fault to a kernel address or a page fault to a user
434-
* address outside of dedicated places
434+
* address outside of dedicated places.
435+
*
436+
* Rather than kfence directly reporting false negatives, search whether
437+
* the NIP belongs to the fixup table for cases where fault could come
438+
* from functions like copy_from_kernel_nofault().
435439
*/
436440
if (unlikely(!is_user && bad_kernel_fault(regs, error_code, address, is_write))) {
437-
if (kfence_handle_page_fault(address, is_write, regs))
441+
if (is_kfence_address((void *)address) &&
442+
!search_exception_tables(instruction_pointer(regs)) &&
443+
kfence_handle_page_fault(address, is_write, regs))
438444
return 0;
439445

440446
return SIGSEGV;

0 commit comments

Comments
 (0)