]> git.ipfire.org Git - people/arne_f/kernel.git/commit
fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info()
authorAlexander Potapenko <glider@google.com>
Thu, 28 May 2020 05:20:52 +0000 (22:20 -0700)
committerBen Hutchings <ben@decadent.org.uk>
Thu, 11 Jun 2020 18:05:58 +0000 (19:05 +0100)
commitd03daec2e50aa2a0b6de2c3572af5e1d61f9d132
treeec44108ac701d6788c6cf42c484a09aed40e33cb
parent493b4e7e4ed9cb671788d886bbc0f8d26ae10dba
fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info()

commit 1d605416fb7175e1adf094251466caa52093b413 upstream.

KMSAN reported uninitialized data being written to disk when dumping
core.  As a result, several kilobytes of kmalloc memory may be written
to the core file and then read by a non-privileged user.

Reported-by: sam <sunhaoyl@outlook.com>
Signed-off-by: Alexander Potapenko <glider@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Acked-by: Kees Cook <keescook@chromium.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Link: http://lkml.kernel.org/r/20200419100848.63472-1-glider@google.com
Link: https://github.com/google/kmsan/issues/76
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[bwh: Backported to 3.16: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
fs/binfmt_elf.c