Files
Linux/include/linux
Pavel Tatashin 3010f87650 mm: discard memblock data later
There is existing use after free bug when deferred struct pages are
enabled:

The memblock_add() allocates memory for the memory array if more than
128 entries are needed.  See comment in e820__memblock_setup():

  * The bootstrap memblock region count maximum is 128 entries
  * (INIT_MEMBLOCK_REGIONS), but EFI might pass us more E820 entries
  * than that - so allow memblock resizing.

This memblock memory is freed here:
        free_low_memory_core_early()

We access the freed memblock.memory later in boot when deferred pages
are initialized in this path:

        deferred_init_memmap()
                for_each_mem_pfn_range()
                  __next_mem_pfn_range()
                    type = &memblock.memory;

One possible explanation for why this use-after-free hasn't been hit
before is that the limit of INIT_MEMBLOCK_REGIONS has never been
exceeded at least on systems where deferred struct pages were enabled.

Tested by reducing INIT_MEMBLOCK_REGIONS down to 4 from the current 128,
and verifying in qemu that this code is getting excuted and that the
freed pages are sane.

Link: http://lkml.kernel.org/r/[email protected]
Fixes: 7e18adb4f8 ("mm: meminit: initialise remaining struct pages in parallel with kswapd")
Signed-off-by: Pavel Tatashin <[email protected]>
Reviewed-by: Steven Sistare <[email protected]>
Reviewed-by: Daniel Jordan <[email protected]>
Reviewed-by: Bob Picco <[email protected]>
Acked-by: Michal Hocko <[email protected]>
Cc: Mel Gorman <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
2017-08-18 15:32:01 -07:00
..
…
…
…
…
…
…
…
…
2017-06-03 19:29:26 +09:00
2017-07-03 01:43:45 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-08 18:52:36 -07:00
2017-07-03 17:00:59 -06:00
…
…
…
…
2017-07-06 16:24:33 -07:00
2017-07-01 16:15:13 -07:00
2017-07-03 02:22:52 -07:00
…
…
…
…
…
…
2017-07-03 16:56:28 -06:00
…
…
…
…
…
…
2017-06-05 16:59:12 +02:00
…
…
…
…
…
…
…
2017-06-22 15:43:47 +01:00
…
…
…
…
2017-06-09 11:52:07 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-07 20:09:10 -04:00
…
…
2017-06-05 16:59:10 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-21 14:37:12 -04:00
…
…
…
…
2017-07-10 16:32:34 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-31 22:01:21 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-10 13:41:04 -04:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-08-18 15:32:01 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-13 16:00:15 -04:00
…
…
…
2017-07-12 16:26:02 -07:00
…
2017-07-06 11:30:07 -04:00
…
…
2017-07-25 18:05:25 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-29 10:48:57 +01:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-12 23:11:23 +02:00
2017-06-08 10:35:49 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-06 16:24:30 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-15 12:12:40 -04:00
…
…
…
…
…
…
…
2017-06-08 18:52:42 -07:00
…
…
…
…
…
2017-06-01 14:53:04 -04:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-07-24 17:50:37 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-09 11:54:54 +02:00
2017-08-18 15:32:01 -07:00
…
…
…
…
…
…
…
…
…
…
…