]> git.ipfire.org Git - thirdparty/qemu.git/commit
linux-user: Prohibit brk() to to shrink below initial heap address
authorHelge Deller <deller@gmx.de>
Mon, 17 Jul 2023 10:27:13 +0000 (12:27 +0200)
committerHelge Deller <deller@gmx.de>
Tue, 18 Jul 2023 18:42:05 +0000 (20:42 +0200)
commitdfe49864afb06e7e452a4366051697bc4fcfc1a5
treeec22a25082c603fd2b77351f42f4f85face4f4de
parent15ad98536ad9410fb32ddf1ff09389b677643faa
linux-user: Prohibit brk() to to shrink below initial heap address

Since commit 86f04735ac ("linux-user: Fix brk() to release pages") it's
possible for userspace applications to reduce their memory footprint by
calling brk() with a lower address and free up memory. Before that commit
guest heap memory was never unmapped.

But the Linux kernel prohibits to reduce brk() below the initial memory
address which is set at startup by the set_brk() function in binfmt_elf.c.
Such a range check was missed in commit 86f04735ac.

This patch adds the missing check by storing the initial brk value in
initial_target_brk and verify any new brk addresses against that value.

Tested with the i386 upx binary from
https://github.com/upx/upx/releases/download/v4.0.2/upx-4.0.2-i386_linux.tar.xz

Signed-off-by: Helge Deller <deller@gmx.de>
Tested-by: "Markus F.X.J. Oberhumer" <markus@oberhumer.com>
Fixes: 86f04735ac ("linux-user: Fix brk() to release pages")
Cc: qemu-stable@nongnu.org
Buglink: https://github.com/upx/upx/issues/683
linux-user/syscall.c