From patchwork Mon Mar 13 09:58:29 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marc Zyngier X-Patchwork-Id: 9620399 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id BAD9260492 for ; Mon, 13 Mar 2017 09:59:01 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id ACA052845C for ; Mon, 13 Mar 2017 09:59:01 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id A122B2845E; Mon, 13 Mar 2017 09:59:01 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID autolearn=unavailable version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [65.50.211.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 05EB82840E for ; Mon, 13 Mar 2017 09:59:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:Date: Message-ID:From:References:To:Subject:Reply-To:Content-ID:Content-Description :Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=UqA5WcIHM9iEclUlSZ+Z7+Ir62kOaDENq8BeHfXrcig=; b=FV1dtOpeR5R8zA qdz0bLiGgYPLcRSnJJGUk/659tKVpEkYg1Nf2FxclKvw/5vv+cyGdpvr5bW1V95QZDxxGfOPj89Se FjYhXMc4deByVlA29vlMs0h0EmlCAVHU88MXJ0kCwO8vOuE4XyOX+Q7HtBono8PCJ8lW1Cipul6Oi 8wSSj6rt/5hlEK584Um2fMPhrwop6/iHx8oP4o1dChO/+G2W+sI/7/DXmqCuwRcVoF+CMRwkkNk1E uzzgQWcg2QlXnukoNkX6oibK0mS+XVTMlnJCu7SvzylC2/R0lqNjBZoQpQ98ZXPAbN7xGoAgr4drR VwML0JvpsBY6bdtrvX4g==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.87 #1 (Red Hat Linux)) id 1cnMkm-0008Cf-J9; Mon, 13 Mar 2017 09:59:00 +0000 Received: from foss.arm.com ([217.140.101.70]) by bombadil.infradead.org with esmtp (Exim 4.87 #1 (Red Hat Linux)) id 1cnMki-00089e-84 for linux-arm-kernel@lists.infradead.org; Mon, 13 Mar 2017 09:58:58 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.72.51.249]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 9A8462B; Mon, 13 Mar 2017 02:58:34 -0700 (PDT) Received: from [10.1.207.16] (usa-sjc-imap-foss1.foss.arm.com [10.72.51.249]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 60FD13F3E1; Mon, 13 Mar 2017 02:58:31 -0700 (PDT) Subject: Re: kvm/arm64: use-after-free in kvm_vm_ioctl/vmacache_update To: Suzuki K Poulose , Andrey Konovalov , Paolo Bonzini , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Christoffer Dall , Catalin Marinas , Will Deacon , Ingo Molnar , Michal Hocko , Christian Borntraeger , Suraj Jitindar Singh , Markus Elfring , Lorenzo Stoakes , kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu, LKML References: <3a57c408-8aa5-d339-4176-add4924e817d@arm.com> From: Marc Zyngier Organization: ARM Ltd Message-ID: <0fc0380f-f108-7d20-ee8a-1b044fa1f115@arm.com> Date: Mon, 13 Mar 2017 09:58:29 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Icedove/45.6.0 MIME-Version: 1.0 In-Reply-To: <3a57c408-8aa5-d339-4176-add4924e817d@arm.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20170313_025856_321300_3CE6BB33 X-CRM114-Status: GOOD ( 14.05 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Kostya Serebryany , syzkaller , Dmitry Vyukov Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP On 10/03/17 18:37, Suzuki K Poulose wrote: > On 10/03/17 15:50, Andrey Konovalov wrote: >> On Fri, Mar 10, 2017 at 2:38 PM, Andrey Konovalov wrote: >>> Hi, >>> >>> I've got the following error report while fuzzing the kernel with syzkaller. >>> >>> On linux-next commit 56b8bad5e066c23e8fa273ef5fba50bd3da2ace8 (Mar 8). >>> >>> Unfortunately I can't reproduce it. >>> >>> ================================================================== >>> BUG: KASAN: use-after-free in vmacache_update+0x114/0x118 mm/vmacache.c:63 >>> Read of size 8 at addr ffff80003b9a2040 by task syz-executor/26615 >>> >>> CPU: 1 PID: 26615 Comm: syz-executor Not tainted >>> 4.11.0-rc1-next-20170308-xc2-dirty #3 >>> Hardware name: Hardkernel ODROID-C2 (DT) >>> Call trace: >>> [] dump_backtrace+0x0/0x440 arch/arm64/kernel/traps.c:505 >>> [] show_stack+0x20/0x30 arch/arm64/kernel/traps.c:228 >>> [] __dump_stack lib/dump_stack.c:16 [inline] >>> [] dump_stack+0x110/0x168 lib/dump_stack.c:52 >>> [] print_address_description+0x60/0x248 mm/kasan/report.c:250 >>> [] kasan_report_error+0xe8/0x250 mm/kasan/report.c:349 >>> [] kasan_report mm/kasan/report.c:372 [inline] >>> [] __asan_report_load8_noabort+0x3c/0x48 mm/kasan/report.c:393 >>> [] vmacache_update+0x114/0x118 mm/vmacache.c:63 >>> [] find_vma+0xf8/0x150 mm/mmap.c:2124 >>> [] kvm_arch_prepare_memory_region+0x2ac/0x488 >>> arch/arm64/kvm/../../../arch/arm/kvm/mmu.c:1817 >>> [] __kvm_set_memory_region+0x3d8/0x12b8 >>> arch/arm64/kvm/../../../virt/kvm/kvm_main.c:1026 >>> [] kvm_set_memory_region+0x38/0x58 >>> arch/arm64/kvm/../../../virt/kvm/kvm_main.c:1075 >>> [] kvm_vm_ioctl_set_memory_region >>> arch/arm64/kvm/../../../virt/kvm/kvm_main.c:1087 [inline] >>> [] kvm_vm_ioctl+0xb94/0x1308 >>> arch/arm64/kvm/../../../virt/kvm/kvm_main.c:2960 >>> [] vfs_ioctl fs/ioctl.c:45 [inline] >>> [] do_vfs_ioctl+0x128/0xfc0 fs/ioctl.c:685 >>> [] SYSC_ioctl fs/ioctl.c:700 [inline] >>> [] SyS_ioctl+0xa8/0xb8 fs/ioctl.c:691 >>> [] el0_svc_naked+0x24/0x28 >>> >>> Allocated by task 26657: >>> save_stack_trace_tsk+0x0/0x330 arch/arm64/kernel/stacktrace.c:133 >>> save_stack_trace+0x20/0x30 arch/arm64/kernel/stacktrace.c:216 >>> save_stack mm/kasan/kasan.c:515 [inline] >>> set_track mm/kasan/kasan.c:527 [inline] >>> kasan_kmalloc+0xd4/0x180 mm/kasan/kasan.c:619 >>> kasan_slab_alloc+0x14/0x20 mm/kasan/kasan.c:557 >>> slab_post_alloc_hook mm/slab.h:456 [inline] >>> slab_alloc_node mm/slub.c:2718 [inline] >>> slab_alloc mm/slub.c:2726 [inline] >>> kmem_cache_alloc+0x144/0x230 mm/slub.c:2731 >>> __split_vma+0x118/0x608 mm/mmap.c:2515 >>> do_munmap+0x194/0x9b0 mm/mmap.c:2636 >>> Freed by task 26657: >>> save_stack_trace_tsk+0x0/0x330 arch/arm64/kernel/stacktrace.c:133 >>> save_stack_trace+0x20/0x30 arch/arm64/kernel/stacktrace.c:216 >>> save_stack mm/kasan/kasan.c:515 [inline] >>> set_track mm/kasan/kasan.c:527 [inline] >>> kasan_slab_free+0x84/0x198 mm/kasan/kasan.c:592 >>> slab_free_hook mm/slub.c:1357 [inline] >>> slab_free_freelist_hook mm/slub.c:1379 [inline] >>> slab_free mm/slub.c:2961 [inline] >>> kmem_cache_free+0x80/0x258 mm/slub.c:2983 >>> __vma_adjust+0x6b0/0xf mm/mmap.c:890] el0_svc_naked+0x24/0x28 >>> >>> The buggy address belongs to the object at ffff80003b9a2000 >>> which belongs to the cache vm_area_struct(647:session-6.scope) of size 184 >>> The buggy address is located 64 bytes inside of >>> 184-byte region [ffff80003b9a2000, ffff80003b9a20b8) >>> The buggy address belongs to the page: >>> page:ffff7e0000ee6880 count:1 mapcount:0 mapping: (null) index:0x0 >>> flags: 0xfffc00000000100(slab) >>> raw: 0fffc00000000100 0000000000000000 0000000000000000 0000000180100010 >>> raw: 0000000000000000 0000000c00000001 ffff80005a5cc600 ffff80005ac99980 >>> page dumped because: kasan: bad access detected >>> page->mem_cgroup:ffff80005ac99980 >>> >>> Memory state around the buggy address: >>> ffff80003b9a1f00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff >>> ffff80003b9a1f80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff >>>> ffff80003b9a2000: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb >>> ^ >>> ffff80003b9a2080: fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc fb >>> ffff80003b9a2100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb >>> ================================================================== >> >> Another one that looks related and doesn't have parts of stack traces missing: >> >> ================================================================== >> BUG: KASAN: use-after-free in find_vma+0x140/0x150 mm/mmap.c:2114 >> Read of size 8 at addr ffff800031a03e90 by task syz-executor/4360 >> >> CPU: 2 PID: 4360 Comm: syz-executor Not tainted >> 4.11.0-rc1-next-20170308-xc2-dirty #3 >> Hardware name: Hardkernel ODROID-C2 (DT) >> Call trace: >> [] dump_backtrace+0x0/0x440 arch/arm64/kernel/traps.c:505 >> [] show_stack+0x20/0x30 arch/arm64/kernel/traps.c:228 >> [] __dump_stack lib/dump_stack.c:16 [inline] >> [] dump_stack+0x110/0x168 lib/dump_stack.c:52 >> [] print_address_description+0x60/0x248 mm/kasan/report.c:250 >> [] kasan_report_error+0xe8/0x250 mm/kasan/report.c:349 >> [] kasan_report mm/kasan/report.c:372 [inline] >> [] __asan_report_load8_noabort+0x3c/0x48 mm/kasan/report.c:393 >> [] find_vma+0x140/0x150 mm/mmap.c:2114 >> [] kvm_arch_prepare_memory_region+0x2ac/0x488 >> arch/arm64/kvm/../../../arch/arm/kvm/mmu.c:1817 > > It looks like we don't take the mmap_sem before calling find_vma() in > stage2_unmap_memslot() and in kvm_arch_prepare_memory_region(), which is causing > the race, with probably the test trying to unmap ranges in between. That indeed seems like a possible failure mode. The annoying thing is that we're not exactly in a position to take mmap_sem in stage2_unmap_memslot, since we hold the kvm->mmu_lock spinlock. We may have to hold mmap_sem while iterating over all the memslots. How about the following (very lightly tested): I'm much more worried about the other report, as I don't really see yet how it happens. Coffee required. Thanks, M. diff --git a/arch/arm/kvm/mmu.c b/arch/arm/kvm/mmu.c index 962616fd4ddd..2006a79d5912 100644 --- a/arch/arm/kvm/mmu.c +++ b/arch/arm/kvm/mmu.c @@ -803,6 +803,7 @@ void stage2_unmap_vm(struct kvm *kvm) int idx; idx = srcu_read_lock(&kvm->srcu); + down_read(¤t->mm->mmap_sem); spin_lock(&kvm->mmu_lock); slots = kvm_memslots(kvm); @@ -810,6 +811,7 @@ void stage2_unmap_vm(struct kvm *kvm) stage2_unmap_memslot(kvm, memslot); spin_unlock(&kvm->mmu_lock); + up_read(¤t->mm->mmap_sem); srcu_read_unlock(&kvm->srcu, idx); } @@ -1813,6 +1815,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm, * | memory region | * +--------------------------------------------+ */ + down_read(¤t->mm->mmap_sem); do { struct vm_area_struct *vma = find_vma(current->mm, hva); hva_t vm_start, vm_end; @@ -1857,7 +1860,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm, } while (hva < reg_end); if (change == KVM_MR_FLAGS_ONLY) - return ret; + goto out; spin_lock(&kvm->mmu_lock); if (ret) @@ -1865,6 +1868,9 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm, else stage2_flush_memslot(kvm, memslot); spin_unlock(&kvm->mmu_lock); + +out: + up_read(¤t->mm->mmap_sem); return ret; }