From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.5 required=3.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6F4D1C433E2 for ; Sat, 12 Sep 2020 15:51:28 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id BA6D0207EA for ; Sat, 12 Sep 2020 15:51:27 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=bytedance-com.20150623.gappssmtp.com header.i=@bytedance-com.20150623.gappssmtp.com header.b="w6jbt/CY" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org BA6D0207EA Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=bytedance.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id EBD486B0002; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id E6DE36B0037; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id D5C956B0055; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0224.hostedemail.com [216.40.44.224]) by kanga.kvack.org (Postfix) with ESMTP id BE1EA6B0002 for ; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) Received: from smtpin11.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay02.hostedemail.com (Postfix) with ESMTP id 6D5C79990 for ; Sat, 12 Sep 2020 15:51:26 +0000 (UTC) X-FDA: 77254848972.11.twig60_1a18255270f8 Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin11.hostedemail.com (Postfix) with ESMTP id 45796180F8B81 for ; Sat, 12 Sep 2020 15:51:26 +0000 (UTC) X-HE-Tag: twig60_1a18255270f8 X-Filterd-Recvd-Size: 4893 Received: from mail-pl1-f193.google.com (mail-pl1-f193.google.com [209.85.214.193]) by imf31.hostedemail.com (Postfix) with ESMTP for ; Sat, 12 Sep 2020 15:51:25 +0000 (UTC) Received: by mail-pl1-f193.google.com with SMTP id y6so2366995plt.9 for ; Sat, 12 Sep 2020 08:51:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bytedance-com.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=5MxdQf9tv8eKzDg+x6Dz/JKJDrhNk6PlqBxr5x7bwNs=; b=w6jbt/CYSIpBugZJMVeS5NXurkdpxIawr2/+p5QKDl9ySs+weYpHK8k+foGfrwF4Tp 3OlxZZtGbi+3nDmKvs49wq0tcgm9aKlYhWTR3UW1f/XpTCA0ZN0qDZMrLgLDaz9VHxNj ZcDSWsLbsvbivWVPnacSeT37LPh5zNjNIlIOIzxFVJUJ0Fdx3y6mzxqX1c+s+u8dQSbA XlmPiOQeEZmWRaZs5WdzCjuHeBaNEWWN5v4HH3Skq/8Bptolk093bINUyVF1DDCcDgTk pf21/VIdwJvxHEGlpJmjwRF//wmPw7y7qPJ1p9FZ/xfr2LTYJpx2g6S1fnvTOGwRpLT+ csKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=5MxdQf9tv8eKzDg+x6Dz/JKJDrhNk6PlqBxr5x7bwNs=; b=L0I4Q2lRp92HRwxv9PhwF7Vo+o1j9W3CQiJFrbvd0QFnns87UMavUNmI9JbORS42Cm 7QXd4+w0oLSek91uLOEeE/jSae3Nyib5wJDQIpbyAPUe81kge/DY/BLFL0nE/3qd0kae UbNZLXWhwvOgSzw77qJ70iKAJya4FLIUbg7fx3DKKS1KcXRPiU1hx+DOANjQS4WH4ZYW a85bFIbCIPnZgv4oLBi9mdGCnYEpnj01zM7AFTaf1kB33KnducpeFFEq9CoYtfraU9dX /ffrzTvZny7OON19B41zA6D51eTmD6NMZw0dAHQwHbh9XmXCvhQ4JPNEIwESIx0KfDnt Pq6A== X-Gm-Message-State: AOAM533cXpzWEF+XjSx0kxb0I4sI7fC2DyToSjkzRc+LiFkFQSPoJgcT y2NqmhuQQYog3zn/XfMkoEPb8A== X-Google-Smtp-Source: ABdhPJy6/dMj1soW8/OLyYEGy7kbZ4UUlnazKCDGWJoQx26D4vqSHo2SJCAuXiLCgyi3+OIje1XQEg== X-Received: by 2002:a17:90a:f415:: with SMTP id ch21mr7118293pjb.18.1599925884681; Sat, 12 Sep 2020 08:51:24 -0700 (PDT) Received: from localhost.localdomain ([103.136.221.70]) by smtp.gmail.com with ESMTPSA id kf10sm4691156pjb.2.2020.09.12.08.51.21 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 12 Sep 2020 08:51:23 -0700 (PDT) From: Muchun Song To: hannes@cmpxchg.org, mhocko@kernel.org, vdavydov.dev@gmail.com, akpm@linux-foundation.org Cc: cgroups@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Muchun Song Subject: [PATCH] mm: memcontrol: Fix out-of-bounds on the buf returned by memory_stat_format Date: Sat, 12 Sep 2020 23:51:00 +0800 Message-Id: <20200912155100.25578-1-songmuchun@bytedance.com> X-Mailer: git-send-email 2.21.0 (Apple Git-122) MIME-Version: 1.0 X-Rspamd-Queue-Id: 45796180F8B81 X-Spamd-Result: default: False [0.00 / 100.00] X-Rspamd-Server: rspam01 Content-Transfer-Encoding: quoted-printable X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: The memory_stat_format() returns a format string, but the return buf may not including the trailing '\0'. So the users may read the buf out of bounds. Fixes: c8713d0b2312 ("mm: memcontrol: dump memory.stat during cgroup OOM"= ) Signed-off-by: Muchun Song --- mm/memcontrol.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/mm/memcontrol.c b/mm/memcontrol.c index f2ef9a770eeb..20c8a1080074 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -1492,12 +1492,13 @@ static bool mem_cgroup_wait_acct_move(struct mem_= cgroup *memcg) return false; } =20 -static char *memory_stat_format(struct mem_cgroup *memcg) +static const char *memory_stat_format(struct mem_cgroup *memcg) { struct seq_buf s; int i; =20 - seq_buf_init(&s, kmalloc(PAGE_SIZE, GFP_KERNEL), PAGE_SIZE); + /* Reserve a byte for the trailing null */ + seq_buf_init(&s, kmalloc(PAGE_SIZE, GFP_KERNEL), PAGE_SIZE - 1); if (!s.buffer) return NULL; =20 @@ -1606,7 +1607,8 @@ static char *memory_stat_format(struct mem_cgroup *= memcg) #endif /* CONFIG_TRANSPARENT_HUGEPAGE */ =20 /* The above should easily fit into one page */ - WARN_ON_ONCE(seq_buf_has_overflowed(&s)); + if (WARN_ON_ONCE(seq_buf_putc(&s, '\0'))) + s.buffer[PAGE_SIZE - 1] =3D '\0'; =20 return s.buffer; } @@ -1644,7 +1646,7 @@ void mem_cgroup_print_oom_context(struct mem_cgroup= *memcg, struct task_struct * */ void mem_cgroup_print_oom_meminfo(struct mem_cgroup *memcg) { - char *buf; + const char *buf; =20 pr_info("memory: usage %llukB, limit %llukB, failcnt %lu\n", K((u64)page_counter_read(&memcg->memory)), @@ -6415,7 +6417,7 @@ static int memory_events_local_show(struct seq_file= *m, void *v) static int memory_stat_show(struct seq_file *m, void *v) { struct mem_cgroup *memcg =3D mem_cgroup_from_seq(m); - char *buf; + const char *buf; =20 buf =3D memory_stat_format(memcg); if (!buf) --=20 2.20.1