From: Greg Kroah-Hartman Date: Wed, 4 Sep 2019 10:31:49 +0000 (+0200) Subject: 4.4-stable patches X-Git-Tag: v4.4.191~13 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=e6eaadd4e9ef7020b134e9e9357dade5663f5680;p=thirdparty%2Fkernel%2Fstable-queue.git 4.4-stable patches added patches: x86-ptrace-fix-up-botched-merge-of-spectrev1-fix.patch --- diff --git a/queue-4.4/series b/queue-4.4/series index 1eb97019ca1..94532be91e3 100644 --- a/queue-4.4/series +++ b/queue-4.4/series @@ -74,3 +74,4 @@ stm-class-fix-a-double-free-of-stm_source_device.patch vmci-release-resource-if-the-work-is-already-queued.patch revert-cfg80211-fix-processing-world-regdomain-when-non-modular.patch mac80211-fix-possible-sta-leak.patch +x86-ptrace-fix-up-botched-merge-of-spectrev1-fix.patch diff --git a/queue-4.4/x86-ptrace-fix-up-botched-merge-of-spectrev1-fix.patch b/queue-4.4/x86-ptrace-fix-up-botched-merge-of-spectrev1-fix.patch new file mode 100644 index 00000000000..166829a8b78 --- /dev/null +++ b/queue-4.4/x86-ptrace-fix-up-botched-merge-of-spectrev1-fix.patch @@ -0,0 +1,40 @@ +From d91372b3cc092fb573ad0ed3edba584dcc3913da Mon Sep 17 00:00:00 2001 +From: Greg Kroah-Hartman +Date: Wed, 4 Sep 2019 12:27:18 +0200 +Subject: x86/ptrace: fix up botched merge of spectrev1 fix + +From: Greg Kroah-Hartman + +I incorrectly merged commit 31a2fbb390fe ("x86/ptrace: Fix possible +spectre-v1 in ptrace_get_debugreg()") when backporting it, as was +graciously pointed out at +https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.php + +Resolve the upstream difference with the stable kernel merge to properly +protect things. + +Reported-by: Brad Spengler +Cc: Dianzhang Chen +Cc: Thomas Gleixner +Cc: +Cc: +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kernel/ptrace.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +--- a/arch/x86/kernel/ptrace.c ++++ b/arch/x86/kernel/ptrace.c +@@ -698,11 +698,10 @@ static unsigned long ptrace_get_debugreg + { + struct thread_struct *thread = &tsk->thread; + unsigned long val = 0; +- int index = n; + + if (n < HBP_NUM) { ++ int index = array_index_nospec(n, HBP_NUM); + struct perf_event *bp = thread->ptrace_bps[index]; +- index = array_index_nospec(index, HBP_NUM); + + if (bp) + val = bp->hw.info.address;