• William Lee Irwin III's avatar
    [PATCH] try_to_unmap_cluster() passes out-of-bounds pte to pte_unmap() · cafdd8ba
    William Lee Irwin III authored
    try_to_unmap_cluster() does:
            for (pte = pte_offset_map(pmd, address);
                            address < end; pte++, address += PAGE_SIZE) {
    		...
    	}
    
    	pte_unmap(pte);
    
    It may take a little staring to notice, but pte can actually fall off the
    end of the pte page in this iteration, which makes life difficult for
    kmap_atomic() and the users not expecting it to BUG().  Of course, we're
    somewhat lucky in that arithmetic elsewhere in the function guarantees that
    at least one iteration is made, lest this force larger rearrangements to be
    made.  This issue and patch also apply to non-mm mainline and with trivial
    adjustments, at least two related kernels.
    
    Discovered during internal testing at Oracle.
    Signed-off-by: default avatarWilliam Irwin <wli@holomorphy.com>
    Signed-off-by: default avatarAndrew Morton <akpm@osdl.org>
    Signed-off-by: default avatarLinus Torvalds <torvalds@osdl.org>
    cafdd8ba
rmap.c 22.7 KB