Commit b75a43d
committed
[HUST CSE][dfs] fix stack buffer overflow on long path components in devtmpfs
_path_separate() and _get_subdir() copied an unbounded path component into
caller-provided buffers, so a single component longer than DIRENT_NAME_MAX
(256) bytes overran the 256-byte file_name[]/subdir_name[] stack arrays used
by devtmpfs_create_vnode() and devtmpfs_file_lookup().
dentry->pathname can be up to DFS_PATH_MAX - 4 = 4092 bytes because
_dentry_create() only strips the mount point prefix, so the overflow length
and its contents are attacker controlled. It is reachable from
open("/dev/<long name>", O_CREAT) - including from user mode through
sys_open() - and from the msh command mkdir /dev/<long name>.
On bsp/qemu-vexpress-a9 an over-long single component produced a data abort
whose backtrace contained 0x41414141, i.e. the saved return address
overwritten with the attacker supplied path bytes.
The tmpfs implementation already validates these lengths and returns
-ENAMETOOLONG (dfs_tmpfs.c), this brings devtmpfs in line with it:
- pass parent_size/file_size to _path_separate() and name_size to
_get_subdir(), rejecting oversized components with -ENAMETOOLONG
- check the return value at both call sites; create_vnode() and
file_lookup() now fail cleanly instead of corrupting the stack
[HUST CSE]1 parent 386b877 commit b75a43d
1 file changed
Lines changed: 48 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
57 | | - | |
| 57 | + | |
| 58 | + | |
58 | 59 | | |
59 | 60 | | |
| 61 | + | |
60 | 62 | | |
61 | 63 | | |
62 | 64 | | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
63 | 71 | | |
| 72 | + | |
64 | 73 | | |
65 | 74 | | |
66 | 75 | | |
| |||
77 | 86 | | |
78 | 87 | | |
79 | 88 | | |
80 | | - | |
81 | | - | |
82 | | - | |
83 | | - | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
84 | 100 | | |
85 | 101 | | |
86 | 102 | | |
| |||
94 | 110 | | |
95 | 111 | | |
96 | 112 | | |
97 | | - | |
| 113 | + | |
98 | 114 | | |
99 | 115 | | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
100 | 123 | | |
101 | 124 | | |
102 | 125 | | |
103 | 126 | | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
104 | 132 | | |
105 | 133 | | |
106 | 134 | | |
| 135 | + | |
107 | 136 | | |
| 137 | + | |
108 | 138 | | |
109 | 139 | | |
110 | 140 | | |
| |||
213 | 243 | | |
214 | 244 | | |
215 | 245 | | |
216 | | - | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
217 | 250 | | |
218 | 251 | | |
219 | 252 | | |
| |||
490 | 523 | | |
491 | 524 | | |
492 | 525 | | |
| 526 | + | |
493 | 527 | | |
494 | 528 | | |
495 | 529 | | |
| |||
503 | 537 | | |
504 | 538 | | |
505 | 539 | | |
506 | | - | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
507 | 547 | | |
508 | 548 | | |
509 | 549 | | |
| |||
0 commit comments