]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
3.16-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 Sep 2014 20:46:16 +0000 (13:46 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 Sep 2014 20:46:16 +0000 (13:46 -0700)
added patches:
module-clean-up-ro-nx-after-early-module-load-failures.patch

queue-3.10/series [new file with mode: 0644]
queue-3.14/series [new file with mode: 0644]
queue-3.16/module-clean-up-ro-nx-after-early-module-load-failures.patch [new file with mode: 0644]
queue-3.16/series [new file with mode: 0644]

diff --git a/queue-3.10/series b/queue-3.10/series
new file mode 100644 (file)
index 0000000..e69de29
diff --git a/queue-3.14/series b/queue-3.14/series
new file mode 100644 (file)
index 0000000..e69de29
diff --git a/queue-3.16/module-clean-up-ro-nx-after-early-module-load-failures.patch b/queue-3.16/module-clean-up-ro-nx-after-early-module-load-failures.patch
new file mode 100644 (file)
index 0000000..c2ad2fc
--- /dev/null
@@ -0,0 +1,41 @@
+From ff7e0055bb5ddbbb320cdd8dfd3e18672bddd2ad Mon Sep 17 00:00:00 2001
+From: Andy Lutomirski <luto@amacapital.net>
+Date: Sat, 16 Aug 2014 04:13:37 +0930
+Subject: module: Clean up ro/nx after early module load failures
+
+From: Andy Lutomirski <luto@amacapital.net>
+
+commit ff7e0055bb5ddbbb320cdd8dfd3e18672bddd2ad upstream.
+
+The commit
+
+    4982223e51e8 module: set nx before marking module MODULE_STATE_COMING.
+
+introduced a regression: if a module fails to parse its arguments or
+if mod_sysfs_setup fails, then the module's memory will be freed
+while still read-only.  Anything that reuses that memory will crash
+as soon as it tries to write to it.
+
+Cc: Rusty Russell <rusty@rustcorp.com.au>
+Signed-off-by: Andy Lutomirski <luto@amacapital.net>
+Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ kernel/module.c |    5 +++++
+ 1 file changed, 5 insertions(+)
+
+--- a/kernel/module.c
++++ b/kernel/module.c
+@@ -3308,6 +3308,11 @@ static int load_module(struct load_info
+       mutex_lock(&module_mutex);
+       module_bug_cleanup(mod);
+       mutex_unlock(&module_mutex);
++
++      /* we can't deallocate the module until we clear memory protection */
++      unset_module_init_ro_nx(mod);
++      unset_module_core_ro_nx(mod);
++
+  ddebug_cleanup:
+       dynamic_debug_remove(info->debug);
+       synchronize_sched();
diff --git a/queue-3.16/series b/queue-3.16/series
new file mode 100644 (file)
index 0000000..618b463
--- /dev/null
@@ -0,0 +1 @@
+module-clean-up-ro-nx-after-early-module-load-failures.patch