]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.17-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 5 Apr 2022 06:03:34 +0000 (08:03 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 5 Apr 2022 06:03:34 +0000 (08:03 +0200)
added patches:
coredump-remove-the-warn_on-in-dump_vma_snapshot.patch

queue-5.17/coredump-remove-the-warn_on-in-dump_vma_snapshot.patch [new file with mode: 0644]
queue-5.17/series

diff --git a/queue-5.17/coredump-remove-the-warn_on-in-dump_vma_snapshot.patch b/queue-5.17/coredump-remove-the-warn_on-in-dump_vma_snapshot.patch
new file mode 100644 (file)
index 0000000..efa899b
--- /dev/null
@@ -0,0 +1,40 @@
+From 49c1866348f364478a0c4d3dd13fd08bb82d3a5b Mon Sep 17 00:00:00 2001
+From: "Eric W. Biederman" <ebiederm@xmission.com>
+Date: Tue, 8 Mar 2022 13:01:19 -0600
+Subject: coredump: Remove the WARN_ON in dump_vma_snapshot
+
+From: Eric W. Biederman <ebiederm@xmission.com>
+
+commit 49c1866348f364478a0c4d3dd13fd08bb82d3a5b upstream.
+
+The condition is impossible and to the best of my knowledge has never
+triggered.
+
+We are in deep trouble if that conditions happens and we walk past
+the end of our allocated array.
+
+So delete the WARN_ON and the code that makes it look like the kernel
+can handle the case of walking past the end of it's vma_meta array.
+
+Reviewed-by: Jann Horn <jannh@google.com>
+Reviewed-by: Kees Cook <keescook@chromium.org>
+Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/coredump.c |    5 -----
+ 1 file changed, 5 deletions(-)
+
+--- a/fs/coredump.c
++++ b/fs/coredump.c
+@@ -1134,11 +1134,6 @@ int dump_vma_snapshot(struct coredump_pa
+       mmap_write_unlock(mm);
+-      if (WARN_ON(i != *vma_count)) {
+-              kvfree(*vma_meta);
+-              return -EFAULT;
+-      }
+-
+       for (i = 0; i < *vma_count; i++) {
+               struct core_vma_metadata *m = (*vma_meta) + i;
index 0ef3ef3e3a620584b857a4f7a3d8ea6675f0e4f6..c6f87c55fd145ffbc59d8f00f2362d3d48398870 100644 (file)
@@ -1120,3 +1120,4 @@ n64cart-convert-bi_disk-to-bi_bdev-bd_disk-fix-build.patch
 revert-nbd-fix-possible-overflow-on-first_minor-in-nbd_dev_add.patch
 mmc-rtsx-let-mmc-core-handle-runtime-pm.patch
 mmc-rtsx-fix-build-errors-warnings-for-unused-variable.patch
+coredump-remove-the-warn_on-in-dump_vma_snapshot.patch