]> git.hungrycats.org Git - linux/commitdiff
openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
authorAli Ahmet Memis <ali@iusegentoo.com>
Fri, 21 Aug 2026 01:45:27 +0000 (01:45 +0000)
committerStafford Horne <shorne@gmail.com>
Sat, 29 Aug 2026 06:32:26 +0000 (07:32 +0100)
sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user
pointers, v1 and v2, and swaps the words they point to in hand-written
assembly.

    l.lwz   r29,0(r4)
    l.lwz   r27,0(r5)
    l.sw    0(r4),r27
    l.sw    0(r5),r29

The pointers are not checked with access_ok(). The four memory
accesses also have no exception table entries.

A caller passes a kernel address as either pointer, and the syscall
reads from and writes to it directly.

This gives an unprivileged process a kernel read/write primitive. It
overwrites kernel data such as the sys_call_table, gaining code
execution in kernel context.

Check both pointers before entering the critical section. Add fixups
for the four memory accesses so faults on valid but unmapped user
addresses return -EFAULT.

[shorne@gmail.com: fix comment style]
Fixes: 9d02a4283e9c ("OpenRISC: Boot code")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Signed-off-by: Stafford Horne <shorne@gmail.com>
arch/openrisc/kernel/entry.S

index c7e90b09645e4dc9dec9af8f9c2b1ab502c1509d..18e68680471eb961a12888cf21ee6d6e95343a29 100644 (file)
@@ -1223,15 +1223,50 @@ _no_syscall_trace:
  *
  */
 
+/* Keep this literal; hi()/lo() can't use the UL-suffixed TASK_SIZE. */
+#define OR1K_ATOMIC_ADDR_LIMIT 0x7ffffffc
+
 ENTRY(sys_or1k_atomic)
        /* FIXME: This ignores r3 and always does an XCHG */
+
+       /* Check both user pointers before accessing them. */
+       l.movhi r13,hi(OR1K_ATOMIC_ADDR_LIMIT)
+       l.ori   r13,r13,lo(OR1K_ATOMIC_ADDR_LIMIT)
+       l.sfgtu r4,r13
+       l.bf    9f
+        l.nop
+       l.sfgtu r5,r13
+       l.bf    9f
+        l.nop
+
        DISABLE_INTERRUPTS(r17,r19)
-       l.lwz   r29,0(r4)
-       l.lwz   r27,0(r5)
-       l.sw    0(r4),r27
-       l.sw    0(r5),r29
+10:    l.lwz   r29,0(r4)
+11:    l.lwz   r27,0(r5)
+12:    l.sw    0(r4),r27
+13:    l.sw    0(r5),r29
        ENABLE_INTERRUPTS(r17)
        l.jr    r9
         l.or   r11,r0,r0
 
+       /*
+        * Either pointer was outside user space, or turned out to be
+        * unmapped/inaccessible when we actually touched it.
+        */
+9:     l.jr    r9
+        l.addi r11,r0,-EFAULT
+
+       .section .fixup, "ax"
+14:
+       ENABLE_INTERRUPTS(r17)
+       l.j     9b
+        l.nop
+       .previous
+
+       .section __ex_table, "a"
+       .long   10b, 14b
+       .long   11b, 14b
+       .long   12b, 14b
+       .long   13b, 14b
+       .previous
+
 /* ============================================================[ EOF ]=== */