From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id B0600CCA473 for ; Sun, 12 Jun 2022 19:52:44 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id CA2B86B0107; Sun, 12 Jun 2022 15:52:43 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id C520B8D0135; Sun, 12 Jun 2022 15:52:43 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id AF2926B0109; Sun, 12 Jun 2022 15:52:43 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id 97AA96B0107 for ; Sun, 12 Jun 2022 15:52:43 -0400 (EDT) Received: from smtpin16.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay13.hostedemail.com (Postfix) with ESMTP id 662F3605C6 for ; Sun, 12 Jun 2022 19:52:43 +0000 (UTC) X-FDA: 79570631406.16.A8AD1FA Received: from casper.infradead.org (casper.infradead.org [90.155.50.34]) by imf25.hostedemail.com (Postfix) with ESMTP id CB157A008C for ; Sun, 12 Jun 2022 19:52:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=casper.20170209; h=In-Reply-To:Content-Type:MIME-Version: References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=xeAFWOF6B2EJpKnlrt3i4hrJP/u9VGwLnbVCf7fZWAw=; b=isOephP5+k8v5pRjwVIAWVR6cY lEHA7FqygtEzTp1JU5OZ6b6e6+XOXm9c/ZVhUCXr4O9dhM5f9gt6O4URae1rodXItRKjaLOpy/C4F jaBQEtS1oHVnWFuseT81gCwAHdPR1lEzAIHyWy950S1ow1JPFFyh7eZ2rlWz2pHMre/8C6+5+8Sm/ y25hyGtR1yK9WRN+GRjgdGSv/4gVRH+701FmaOvVruFQPZa4yNtdHMGr2NG354d235F5hrfj4E6yu NuZV1qSU+hq9oyOn6UoCsI8EkOtUb+FSfdYqLbppJnySUwycftHYPX1EYSe4b+NSo3FM2b8UFRg9Q KwsfOYkQ==; Received: from willy by casper.infradead.org with local (Exim 4.94.2 #2 (Red Hat Linux)) id 1o0TdP-00GEYG-Qh; Sun, 12 Jun 2022 19:52:31 +0000 Date: Sun, 12 Jun 2022 20:52:31 +0100 From: Matthew Wilcox To: Yu Zhao Cc: Uladzislau Rezki , Zorro Lang , Alexander Gordeev , bugzilla-daemon@kernel.org, linux-s390@vger.kernel.org, linux-xfs@vger.kernel.org, Andrew Morton , Linux-MM , Kees Cook Subject: Re: [Bug 216073] New: [s390x] kernel BUG at mm/usercopy.c:101! usercopy: Kernel memory exposure attempt detected from vmalloc 'n o area' (offset 0, size 1)! Message-ID: References: <20220608021922.n2izu7n4yoadknkx@zlang-mailbox> <20220612044230.murerhsa765akogj@zlang-mailbox> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1655063563; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=xeAFWOF6B2EJpKnlrt3i4hrJP/u9VGwLnbVCf7fZWAw=; b=50bYPYfYsrc+/Qwi5DyeJlLCeCTZRt6wbv27tbrNsO4VmXz2oknu/5FMBCLOTdMJQvHaeM Vehdm6ZXfiYm2zUBOJKtK8/x2BpYIVQ93NK2TPZpwLwNYDUHgrsiGuACgBqZ+AVOTf5B96 TV6Co9MmRqrQYCPA4MQYxgxbv3FDcAc= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1655063563; a=rsa-sha256; cv=none; b=aSn8aNk9gH8IKXI0nJR8lxiAQtD0XivrHa1Hpe5ligGFMvhD6EboSWEy/c2u45Ao72i48L HBPQg/hAqmlQO2jnCTM8K1ymGggfSfKp/2UtqZUtGAe1aBsmdX6YrLmu2CzFwEdaKdkc/v 3oR7lz+cUhI7fOfQ8uPAjaL11hcXzTI= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=infradead.org header.s=casper.20170209 header.b=isOephP5; dmarc=none; spf=none (imf25.hostedemail.com: domain of willy@infradead.org has no SPF policy when checking 90.155.50.34) smtp.mailfrom=willy@infradead.org X-Rspam-User: Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=infradead.org header.s=casper.20170209 header.b=isOephP5; dmarc=none; spf=none (imf25.hostedemail.com: domain of willy@infradead.org has no SPF policy when checking 90.155.50.34) smtp.mailfrom=willy@infradead.org X-Rspamd-Server: rspam03 X-Stat-Signature: a14domi1zmpi669qhgdyttr34xptbgih X-Rspamd-Queue-Id: CB157A008C X-HE-Tag: 1655063562-884920 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Sun, Jun 12, 2022 at 12:43:45PM -0600, Yu Zhao wrote: > On Sun, Jun 12, 2022 at 12:05 PM Matthew Wilcox wrote: > > > > On Sun, Jun 12, 2022 at 11:59:58AM -0600, Yu Zhao wrote: > > > Please let me know if there is something we want to test -- I can > > > reproduce the problem reliably: > > > > > > ------------[ cut here ]------------ > > > kernel BUG at mm/usercopy.c:101! > > > > The line right before cut here would have been nice ;-) > > Right. > > $ grep usercopy: > usercopy: Kernel memory exposure attempt detected from vmalloc (offset > 2882303761517129920, size 11)! > usercopy: Kernel memory exposure attempt detected from vmalloc (offset > 8574853690513436864, size 11)! > usercopy: Kernel memory exposure attempt detected from vmalloc (offset > 7998392938210013376, size 11)! That's a different problem. And, er, what? How on earth do we have an offset that big?! struct vm_struct *area = find_vm_area(ptr); offset = ptr - area->addr; if (offset + n > get_vm_area_size(area)) usercopy_abort("vmalloc", NULL, to_user, offset, n); That first offset is 0x2800'0000'0000'30C0 You said it was easy to replicate; can you add: printk("addr:%px ptr:%px\n", area->addr, ptr); so that we can start to understand how we end up with such a bogus offset?