]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/commitdiff
waitid(): Add missing access_ok() checks
authorKees Cook <keescook@chromium.org>
Mon, 9 Oct 2017 18:36:52 +0000 (11:36 -0700)
committerSeth Forshee <seth.forshee@canonical.com>
Tue, 10 Oct 2017 12:13:52 +0000 (07:13 -0500)
Adds missing access_ok() checks.

CVE-2017-5123

Reported-by: Chris Salls <chrissalls5@gmail.com>
Fixes: 4c48abe91be0 ("waitid(): switch copyout of siginfo to unsafe_put_user()")
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
kernel/exit.c

index c5548faa9f377c5bf01f4a4db8e3020448565469..b3c69c3a60b2f6658136581538c4bebdb8583d60 100644 (file)
@@ -1613,6 +1613,9 @@ SYSCALL_DEFINE5(waitid, int, which, pid_t, upid, struct siginfo __user *,
        if (!infop)
                return err;
 
+       if (!access_ok(VERIFY_WRITE, infop, sizeof(*infop)))
+               goto Efault;
+
        user_access_begin();
        unsafe_put_user(signo, &infop->si_signo, Efault);
        unsafe_put_user(0, &infop->si_errno, Efault);
@@ -1739,6 +1742,9 @@ COMPAT_SYSCALL_DEFINE5(waitid,
        if (!infop)
                return err;
 
+       if (!access_ok(VERIFY_WRITE, infop, sizeof(*infop)))
+               goto Efault;
+
        user_access_begin();
        unsafe_put_user(signo, &infop->si_signo, Efault);
        unsafe_put_user(0, &infop->si_errno, Efault);