]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
drm/i915: restrict kernel address leak in debugfs
authorKees Cook <keescook@chromium.org>
Mon, 11 Mar 2013 19:25:19 +0000 (12:25 -0700)
committerBen Hutchings <ben@decadent.org.uk>
Wed, 27 Mar 2013 02:41:13 +0000 (02:41 +0000)
commit 2563a4524febe8f4a98e717e02436d1aaf672aa2 upstream.

Masks kernel address info-leak in object dumps with the %pK suffix,
so they cannot be used to target kernel memory corruption attacks if
the kptr_restrict sysctl is set.

Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
[bwh: Backported to 3.2: the rest of the format string is different]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
drivers/gpu/drm/i915/i915_debugfs.c

index 5620192fd4dc9a8b0f20b668db666b4f5b01a46a..9b4e5c6d1cfba9121d361bf5c8d559e113ad8e1e 100644 (file)
@@ -122,7 +122,7 @@ static const char *cache_level_str(int type)
 static void
 describe_obj(struct seq_file *m, struct drm_i915_gem_object *obj)
 {
-       seq_printf(m, "%p: %s%s %8zd %04x %04x %d %d%s%s%s",
+       seq_printf(m, "%pK: %s%s %8zd %04x %04x %d %d%s%s%s",
                   &obj->base,
                   get_pin_flag(obj),
                   get_tiling_flag(obj),