From patchwork Mon Jul 30 19:01:46 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Tobias Stoeckmann X-Patchwork-Id: 10549595 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 709AC15E2 for ; Mon, 30 Jul 2018 19:01:51 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 5F2F02A666 for ; Mon, 30 Jul 2018 19:01:51 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 5DB352A6F8; Mon, 30 Jul 2018 19:01:51 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.9 required=2.0 tests=BAYES_00,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id CB3872A666 for ; Mon, 30 Jul 2018 19:01:50 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730125AbeG3UiM (ORCPT ); Mon, 30 Jul 2018 16:38:12 -0400 Received: from mout.kundenserver.de ([212.227.126.130]:35508 "EHLO mout.kundenserver.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729561AbeG3UiL (ORCPT ); Mon, 30 Jul 2018 16:38:11 -0400 Received: from localhost ([217.87.206.98]) by mrelayeu.kundenserver.de (mreue004 [212.227.15.129]) with ESMTPSA (Nemesis) id 0MQJuC-1fY1hY0y68-00Tkym for ; Mon, 30 Jul 2018 21:01:48 +0200 Date: Mon, 30 Jul 2018 21:01:46 +0200 From: Tobias Stoeckmann To: linux-modules@vger.kernel.org Subject: [PATCH] Verify memory sizes on 32 bit systems. Message-ID: <20180730190146.GA8535@localhost> MIME-Version: 1.0 Content-Disposition: inline X-Provags-ID: V03:K1:vY28kqKQFkeEoKveI/bXhwQLrooOOeBL3GrTTU2rIbP5nnAg7rR sXHTbOc/IjkExXgtEea5EsoyDOBX/NB2P7Ys2XLd/2lYWvqlKDbamDU2/QHL4J4hLwDimwg uWeQGVaNJMOGs4t/m4hfCSgDKZxsjhX/5pJhqfaKpY5K5dR5XiPrCZRPt2XPEHiyDHHuky1 VexoHA4acvQTaUP7GSAuQ== X-UI-Out-Filterresults: notjunk:1;V01:K0:wzpvb4cOcxE=:S0+i4cfHmY1g5LKJkG6MX3 MQ5gWk+ZH/gXWsm2d3RywaTxdswwykbiDp8Vr36v3csbgY3qRqCp+O5t6p/p+mphl8HLWBH/A MJVprELxVnx/WcjGZ3y1HSqgm8F9Y9nxzaE4p7FVIbVd3Jm6je/LcsvO7dWXBSitLrqI4c9os BqIVLNgbAOfIfhC5zy27ehFnDYtBIrqViV87GVXKFQvk47n1+vnZoX6/qwHM+E18JT8PbtjzZ cBohT9QitCVqPxtCvi+F6mT6dRQX/Jqaa88V4P5FcmkZYUAP93VivAEq9JLfkrISUYvc6Q7Md KqcEWv6Cyk2q7uq17soMNOs0aXo3ZUC3/t5n8GSuqQZjIe/EMzQhHXzF+fG/pMI9wkgfr0wrg CiAqHZg5wLY872vRr+7D+FDSKldR4oRjfh+WuSZ6EUuJR/DcWLYYekSkoVmlC2fGy3uQN2ras 15cyN5LwRvrgkQrwDavckr4AL9ptQTOd8yPojPKgsUquOw3SYnygUuw41m5FQbLZ4nSTMiayc Kc84pqNiX/NQ8S4/q15t+t5QApi5rfHzYP9ZH14EU/8Q6UI9ZXIUoHVnyffFWunhe8x1IsKch 7tuJy6sytYsBTMxGx2q0cDV/i8nu7do9W6NR3vvlkV8FuzCbCM/yJtRQXP61rxxKYYwzuBoMS lF3PIdCbe9/PdbIS+KN+5qZdn3pcppSA7EAHmbJR1aqO3ZSd9RmGtyNqw6+TfU3x0Mmk= Sender: owner-linux-modules@vger.kernel.org Precedence: bulk List-ID: X-Virus-Scanned: ClamAV using ClamSMTP Large file system support is activated by default, which means that on 32 bit systems, off_t is 64 bit in size. Using st.st_size or any other 64 bit variable with mmap can lead to integer truncation and therefore insufficient memory mapping. Signed-off-by: Tobias Stoeckmann --- libkmod/libkmod-file.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libkmod/libkmod-file.c b/libkmod/libkmod-file.c index 5eeba6a..86f34c6 100644 --- a/libkmod/libkmod-file.c +++ b/libkmod/libkmod-file.c @@ -255,6 +255,8 @@ static int load_reg(struct kmod_file *file) return -errno; file->size = st.st_size; + if ((uintmax_t)st.st_size > (uintmax_t)SIZE_MAX) + return -EFBIG; file->memory = mmap(NULL, file->size, PROT_READ, MAP_PRIVATE, file->fd, 0); if (file->memory == MAP_FAILED)