• Ben Hutchings's avatar
    pipe: iovec: Fix memory corruption when retrying atomic copy as non-atomic · eca06b45
    Ben Hutchings authored
    pipe_iov_copy_{from,to}_user() may be tried twice with the same iovec,
    the first time atomically and the second time not.  The second attempt
    needs to continue from the iovec position, pipe buffer offset and
    remaining length where the first attempt failed, but currently the
    pipe buffer offset and remaining length are reset.  This will corrupt
    the piped data (possibly also leading to an information leak between
    processes) and may also corrupt kernel memory.
    
    This was fixed upstream by commits f0d1bec9d58d ("new helper:
    copy_page_from_iter()") and 637b58c2887e ("switch pipe_read() to
    copy_page_to_iter()"), but those aren't suitable for stable.  This fix
    for older kernel versions was made by Seth Jennings for RHEL and I
    have extracted it from their update.
    
    CVE-2015-1805
    
    Bug: 27275324
    
    Change-Id: I459adb9076fcd50ff1f1c557089c4e421b036ec4
    References: https://bugzilla.redhat.com/show_bug.cgi?id=1202855
    
    Signed-off-by: default avatarBen Hutchings <ben@decadent.org.uk>
    Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
    (cherry picked from commit 85c34d007116f8a8aafb173966a605fb03532f45)
    eca06b45
pipe.c 29.3 KB