From: Thomas Gleixner Date: Sun, 8 Apr 2007 23:04:23 +0000 (+0200) Subject: hrtimer: prevent overrun DoS in hrtimer_forward() X-Git-Tag: v2.6.16.47-rc1~3 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=75da4e64268ffdbd56143b4642d340b9bf3ee350;p=thirdparty%2Fkernel%2Fstable.git hrtimer: prevent overrun DoS in hrtimer_forward() hrtimer_forward() does not check for the possible overflow of timer->expires. This can happen on 64 bit machines with large interval values and results currently in an endless loop in the softirq because the expiry value becomes negative and therefor the timer is expired all the time. Check for this condition and set the expiry value to the max. expiry time in the future. Signed-off-by: Thomas Gleixner Signed-off-by: Adrian Bunk --- diff --git a/kernel/hrtimer.c b/kernel/hrtimer.c index 14bc9cfa63999..a29ceb04c257e 100644 --- a/kernel/hrtimer.c +++ b/kernel/hrtimer.c @@ -316,6 +316,12 @@ hrtimer_forward(struct hrtimer *timer, ktime_t interval) orun++; } timer->expires = ktime_add(timer->expires, interval); + /* + * Make sure, that the result did not wrap with a very large + * interval. + */ + if (timer->expires.tv64 < 0) + timer->expires = ktime_set(KTIME_SEC_MAX, 0); return orun; }