From patchwork Sat Sep 12 15:51:00 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Muchun Song X-Patchwork-Id: 11771949 Return-Path: Received: from mail.kernel.org (pdx-korg-mail-1.web.codeaurora.org [172.30.200.123]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 72DAF746 for ; Sat, 12 Sep 2020 15:51:28 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id E958720855 for ; Sat, 12 Sep 2020 15:51:27 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=bytedance-com.20150623.gappssmtp.com header.i=@bytedance-com.20150623.gappssmtp.com header.b="w6jbt/CY" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org E958720855 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=bytedance.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id EBD486B0002; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) Delivered-To: linux-mm-outgoing@kvack.org Received: by kanga.kvack.org (Postfix, from userid 40) id E6DE36B0037; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) X-Original-To: int-list-linux-mm@kvack.org X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id D5C956B0055; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) X-Original-To: linux-mm@kvack.org X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0224.hostedemail.com [216.40.44.224]) by kanga.kvack.org (Postfix) with ESMTP id BE1EA6B0002 for ; Sat, 12 Sep 2020 11:51:26 -0400 (EDT) Received: from smtpin11.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay02.hostedemail.com (Postfix) with ESMTP id 6D5C79990 for ; Sat, 12 Sep 2020 15:51:26 +0000 (UTC) X-FDA: 77254848972.11.twig60_1a18255270f8 Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin11.hostedemail.com (Postfix) with ESMTP id 45796180F8B81 for ; Sat, 12 Sep 2020 15:51:26 +0000 (UTC) X-Spam-Summary: 1,0,0,a3c76bb41812b3ae,d41d8cd98f00b204,songmuchun@bytedance.com,,RULES_HIT:41:355:379:541:800:960:973:988:989:1260:1311:1314:1345:1437:1515:1534:1541:1711:1730:1747:1777:1792:2393:2553:2559:2562:3138:3139:3140:3141:3142:3353:3865:3866:4321:5007:6261:6653:7901:10004:11026:11232:11473:11658:11914:12043:12048:12296:12297:12438:12517:12519:12555:12679:12895:12986:13069:13161:13229:13255:13311:13357:13894:14093:14181:14384:14394:14721:21080:21433:21444:21451:21627:21990:30054:30056:30090,0,RBL:209.85.214.193:@bytedance.com:.lbl8.mailshell.net-66.100.201.201 62.2.0.100;04ygazq1mn9whym85n8o8ebgggjmfoc8bcucydc5qiqeaqc1ui7no7zsw9mf48a.motweembu4acyrdkmb533y5owfsgbutjmn16jmc4ib4yd6c17bba3h1dr8psicx.1-lbl8.mailshell.net-223.238.255.100,CacheIP:none,Bayesian:0.5,0.5,0.5,Netcheck:none,DomainCache:0,MSF:not bulk,SPF:fp,MSBL:0,DNSBL:neutral,Custom_rules:0:0:0,LFtime:24,LUA_SUMMARY:none X-HE-Tag: twig60_1a18255270f8 X-Filterd-Recvd-Size: 4893 Received: from mail-pl1-f193.google.com (mail-pl1-f193.google.com [209.85.214.193]) by imf31.hostedemail.com (Postfix) with ESMTP for ; Sat, 12 Sep 2020 15:51:25 +0000 (UTC) Received: by mail-pl1-f193.google.com with SMTP id y6so2366995plt.9 for ; Sat, 12 Sep 2020 08:51:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bytedance-com.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=5MxdQf9tv8eKzDg+x6Dz/JKJDrhNk6PlqBxr5x7bwNs=; b=w6jbt/CYSIpBugZJMVeS5NXurkdpxIawr2/+p5QKDl9ySs+weYpHK8k+foGfrwF4Tp 3OlxZZtGbi+3nDmKvs49wq0tcgm9aKlYhWTR3UW1f/XpTCA0ZN0qDZMrLgLDaz9VHxNj ZcDSWsLbsvbivWVPnacSeT37LPh5zNjNIlIOIzxFVJUJ0Fdx3y6mzxqX1c+s+u8dQSbA XlmPiOQeEZmWRaZs5WdzCjuHeBaNEWWN5v4HH3Skq/8Bptolk093bINUyVF1DDCcDgTk pf21/VIdwJvxHEGlpJmjwRF//wmPw7y7qPJ1p9FZ/xfr2LTYJpx2g6S1fnvTOGwRpLT+ csKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=5MxdQf9tv8eKzDg+x6Dz/JKJDrhNk6PlqBxr5x7bwNs=; b=L0I4Q2lRp92HRwxv9PhwF7Vo+o1j9W3CQiJFrbvd0QFnns87UMavUNmI9JbORS42Cm 7QXd4+w0oLSek91uLOEeE/jSae3Nyib5wJDQIpbyAPUe81kge/DY/BLFL0nE/3qd0kae UbNZLXWhwvOgSzw77qJ70iKAJya4FLIUbg7fx3DKKS1KcXRPiU1hx+DOANjQS4WH4ZYW a85bFIbCIPnZgv4oLBi9mdGCnYEpnj01zM7AFTaf1kB33KnducpeFFEq9CoYtfraU9dX /ffrzTvZny7OON19B41zA6D51eTmD6NMZw0dAHQwHbh9XmXCvhQ4JPNEIwESIx0KfDnt Pq6A== X-Gm-Message-State: AOAM533cXpzWEF+XjSx0kxb0I4sI7fC2DyToSjkzRc+LiFkFQSPoJgcT y2NqmhuQQYog3zn/XfMkoEPb8A== X-Google-Smtp-Source: ABdhPJy6/dMj1soW8/OLyYEGy7kbZ4UUlnazKCDGWJoQx26D4vqSHo2SJCAuXiLCgyi3+OIje1XQEg== X-Received: by 2002:a17:90a:f415:: with SMTP id ch21mr7118293pjb.18.1599925884681; Sat, 12 Sep 2020 08:51:24 -0700 (PDT) Received: from localhost.localdomain ([103.136.221.70]) by smtp.gmail.com with ESMTPSA id kf10sm4691156pjb.2.2020.09.12.08.51.21 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 12 Sep 2020 08:51:23 -0700 (PDT) From: Muchun Song To: hannes@cmpxchg.org, mhocko@kernel.org, vdavydov.dev@gmail.com, akpm@linux-foundation.org Cc: cgroups@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Muchun Song Subject: [PATCH] mm: memcontrol: Fix out-of-bounds on the buf returned by memory_stat_format Date: Sat, 12 Sep 2020 23:51:00 +0800 Message-Id: <20200912155100.25578-1-songmuchun@bytedance.com> X-Mailer: git-send-email 2.21.0 (Apple Git-122) MIME-Version: 1.0 X-Rspamd-Queue-Id: 45796180F8B81 X-Spamd-Result: default: False [0.00 / 100.00] X-Rspamd-Server: rspam01 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: The memory_stat_format() returns a format string, but the return buf may not including the trailing '\0'. So the users may read the buf out of bounds. Fixes: c8713d0b2312 ("mm: memcontrol: dump memory.stat during cgroup OOM") Signed-off-by: Muchun Song --- mm/memcontrol.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/mm/memcontrol.c b/mm/memcontrol.c index f2ef9a770eeb..20c8a1080074 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -1492,12 +1492,13 @@ static bool mem_cgroup_wait_acct_move(struct mem_cgroup *memcg) return false; } -static char *memory_stat_format(struct mem_cgroup *memcg) +static const char *memory_stat_format(struct mem_cgroup *memcg) { struct seq_buf s; int i; - seq_buf_init(&s, kmalloc(PAGE_SIZE, GFP_KERNEL), PAGE_SIZE); + /* Reserve a byte for the trailing null */ + seq_buf_init(&s, kmalloc(PAGE_SIZE, GFP_KERNEL), PAGE_SIZE - 1); if (!s.buffer) return NULL; @@ -1606,7 +1607,8 @@ static char *memory_stat_format(struct mem_cgroup *memcg) #endif /* CONFIG_TRANSPARENT_HUGEPAGE */ /* The above should easily fit into one page */ - WARN_ON_ONCE(seq_buf_has_overflowed(&s)); + if (WARN_ON_ONCE(seq_buf_putc(&s, '\0'))) + s.buffer[PAGE_SIZE - 1] = '\0'; return s.buffer; } @@ -1644,7 +1646,7 @@ void mem_cgroup_print_oom_context(struct mem_cgroup *memcg, struct task_struct * */ void mem_cgroup_print_oom_meminfo(struct mem_cgroup *memcg) { - char *buf; + const char *buf; pr_info("memory: usage %llukB, limit %llukB, failcnt %lu\n", K((u64)page_counter_read(&memcg->memory)), @@ -6415,7 +6417,7 @@ static int memory_events_local_show(struct seq_file *m, void *v) static int memory_stat_show(struct seq_file *m, void *v) { struct mem_cgroup *memcg = mem_cgroup_from_seq(m); - char *buf; + const char *buf; buf = memory_stat_format(memcg); if (!buf)