From patchwork Mon Feb 2 02:52:11 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: zibo zhao X-Patchwork-Id: 5758661 Return-Path: X-Original-To: patchwork-linux-crypto@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork1.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.136]) by patchwork1.web.kernel.org (Postfix) with ESMTP id 630E89F302 for ; Mon, 2 Feb 2015 02:52:40 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id 921ED2012E for ; Mon, 2 Feb 2015 02:52:39 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id AACCC200FE for ; Mon, 2 Feb 2015 02:52:38 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751762AbbBBCwh (ORCPT ); Sun, 1 Feb 2015 21:52:37 -0500 Received: from mail-ig0-f173.google.com ([209.85.213.173]:64753 "EHLO mail-ig0-f173.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751481AbbBBCwg (ORCPT ); Sun, 1 Feb 2015 21:52:36 -0500 Received: by mail-ig0-f173.google.com with SMTP id a13so15138265igq.0 for ; Sun, 01 Feb 2015 18:52:35 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id; bh=SjwPRaJsnQNVxxmceqPdlIXY8iSmi5qxPKF94EFwh4A=; b=QiH8QQ3Ix0gdRzhTXoJZxz8xE1qZCpGuV4Y2SnA6YhWQ7R7lzSVruGbsGcsvzu6hHz c6x+BpViq3dpA9vFeI1DjdqRtl9qi9XYXvee/Y9tu7kiYCaev4A1KwDP0e2tkTexz789 YvIg4Y/fSsGnDna/0SQ0RhUfm3dtp/V7T0uvr30ZNVlu0tP1SklKwjPUXhyvEpbJnVSd 7xYIbl0+wSaiL54oMV/1KgYnHqeoUw1n7snOYySiXSJtG0NYYrJ08CUA7Q4jgBgR4uCJ bYvwnFSiRXeAYD3xpcPPW8vKUu9j7hWEMk0MbphtdGVaDS5qDJGHONGDUHFnGytLqCeT ZZbg== X-Received: by 10.42.249.2 with SMTP id mi2mr16761723icb.36.1422845555834; Sun, 01 Feb 2015 18:52:35 -0800 (PST) Received: from localhost.localdomain ([135.0.55.10]) by mx.google.com with ESMTPSA id z71sm5342602iod.11.2015.02.01.18.52.18 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sun, 01 Feb 2015 18:52:35 -0800 (PST) From: zibo zhao To: linux-crypto@vger.kernel.org Cc: zibo zhao Subject: [PATCH] crypto: make public_key_subtype data structure read only Date: Sun, 1 Feb 2015 21:52:11 -0500 Message-Id: <1422845531-23895-1-git-send-email-chinabull@gmail.com> X-Mailer: git-send-email 1.9.1 Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org X-Spam-Status: No, score=-6.8 required=5.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_HI, T_DKIM_INVALID, T_RP_MATCHES_RCVD, UNPARSEABLE_RELAY autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP During the attempt to disable the kernel module signing verification in some android kernel, I came across that the public_key_subtype in asymmetric_keys/public_key.c which has following declarations: struct asymmetric_key_subtype public_key_subtype = { ... .describe = public_key_describe, .destroy = public_key_destroy, .verify_signature = public_key_verify_signature_2, }; As long as I have root access and /dev/mem access available, it seems to be quite easy to have kernel module signing verification workarounded by just simply assign the address of public_key_describe() to the .verify_signature data member. This could be avoided by adding const to the data structure to make all the data members ready only. Signed-off-by: zibo zhao --- crypto/asymmetric_keys/public_key.c | 2 +- crypto/asymmetric_keys/public_key.h | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/crypto/asymmetric_keys/public_key.c b/crypto/asymmetric_keys/public_key.c index 2f6e4fb..bf921b8 100644 --- a/crypto/asymmetric_keys/public_key.c +++ b/crypto/asymmetric_keys/public_key.c @@ -118,7 +118,7 @@ static int public_key_verify_signature_2(const struct key *key, /* * Public key algorithm asymmetric key subtype */ -struct asymmetric_key_subtype public_key_subtype = { +const struct asymmetric_key_subtype public_key_subtype = { .owner = THIS_MODULE, .name = "public_key", .name_len = sizeof("public_key") - 1, diff --git a/crypto/asymmetric_keys/public_key.h b/crypto/asymmetric_keys/public_key.h index 5c37a22..751f5c3 100644 --- a/crypto/asymmetric_keys/public_key.h +++ b/crypto/asymmetric_keys/public_key.h @@ -13,7 +13,7 @@ #include -extern struct asymmetric_key_subtype public_key_subtype; +extern const struct asymmetric_key_subtype public_key_subtype; /* * Public key algorithm definition.