openrisc: fix arbitrary kernel memory access via or1k_atomic syscall

sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user
pointers, v1 and v2, and swaps the words they point to in hand-written
assembly.

    l.lwz   r29,0(r4)
    l.lwz   r27,0(r5)
    l.sw    0(r4),r27
    l.sw    0(r5),r29

The pointers are not checked with access_ok(). The four memory
accesses also have no exception table entries.

A caller passes a kernel address as either pointer, and the syscall
reads from and writes to it directly.

This gives an unprivileged process a kernel read/write primitive. It
overwrites kernel data such as the sys_call_table, gaining code
execution in kernel context.

Check both pointers before entering the critical section. Add fixups
for the four memory accesses so faults on valid but unmapped user
addresses return -EFAULT.

[shorne@gmail.com: fix comment style]
Fixes: 9d02a4283e ("OpenRISC: Boot code")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Signed-off-by: Stafford Horne <shorne@gmail.com>
This commit is contained in:
Ali Ahmet Memis 2026-08-21 01:45:27 +00:00 committed by Stafford Horne
parent 6620f5e8c1
commit 78004e9a87

View File

@ -1223,15 +1223,50 @@ _no_syscall_trace:
*
*/
/* Keep this literal; hi()/lo() can't use the UL-suffixed TASK_SIZE. */
#define OR1K_ATOMIC_ADDR_LIMIT 0x7ffffffc
ENTRY(sys_or1k_atomic)
/* FIXME: This ignores r3 and always does an XCHG */
/* Check both user pointers before accessing them. */
l.movhi r13,hi(OR1K_ATOMIC_ADDR_LIMIT)
l.ori r13,r13,lo(OR1K_ATOMIC_ADDR_LIMIT)
l.sfgtu r4,r13
l.bf 9f
l.nop
l.sfgtu r5,r13
l.bf 9f
l.nop
DISABLE_INTERRUPTS(r17,r19)
l.lwz r29,0(r4)
l.lwz r27,0(r5)
l.sw 0(r4),r27
l.sw 0(r5),r29
10: l.lwz r29,0(r4)
11: l.lwz r27,0(r5)
12: l.sw 0(r4),r27
13: l.sw 0(r5),r29
ENABLE_INTERRUPTS(r17)
l.jr r9
l.or r11,r0,r0
/*
* Either pointer was outside user space, or turned out to be
* unmapped/inaccessible when we actually touched it.
*/
9: l.jr r9
l.addi r11,r0,-EFAULT
.section .fixup, "ax"
14:
ENABLE_INTERRUPTS(r17)
l.j 9b
l.nop
.previous
.section __ex_table, "a"
.long 10b, 14b
.long 11b, 14b
.long 12b, 14b
.long 13b, 14b
.previous
/* ============================================================[ EOF ]=== */