mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 20:53:03 +02:00
ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation
with an mmap_count check performed under the PCM stream lock, but the
lock is released long before the buffer is actually freed:
snd_pcm_sync_stop(), constraint refinement and do_free_pages() all
happen in between. snd_pcm_mmap_data(), on the other hand, takes no
lock at all: it validates against the old buffer's state and
dma_bytes, remaps its pages into the VMA, and only then increments
mmap_count.
A concurrent mmap() can therefore slip in between the check and the
free. remap_pfn_range() installs writable PTEs for the old buffer's
pages without taking page references, and the subsequent
do_free_pages() returns those pages to the page allocator while the
VMA still maps them. This leaves a stale, writable mapping of freed
pages: a page-level use-after-free that can be leveraged for local
privilege escalation.
Make snd_pcm_mmap_data() participate in the buffer-access scheme
introduced for hw_params/hw_free: acquire runtime->buffer_accessing
before validating and remapping, and release it afterwards. Buffer
reallocation already fails with -EBUSY while accessors are active,
and the mmap side now fails with -EBUSY while a reallocation is in
progress, so the validate/remap sequence and the check/free sequence
can no longer interleave.
A reproducer that turns this race into a stale writable mapping of
the freed DMA buffer pages is available on request.
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Fixes: 92ee3c60ec ("ALSA: pcm: Fix races among concurrent hw_params and hw_free calls")
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Link: https://patch.msgid.link/20260831045506.889070-1-yilinzhang@moonshot.ai
Signed-off-by: Takashi Iwai <tiwai@suse.de>
This commit is contained in:
parent
33abb7491e
commit
9b110a9dce
|
|
@ -4023,20 +4023,33 @@ int snd_pcm_mmap_data(struct snd_pcm_substream *substream, struct file *file,
|
|||
return -EINVAL;
|
||||
}
|
||||
runtime = substream->runtime;
|
||||
if (runtime->state == SNDRV_PCM_STATE_OPEN)
|
||||
return -EBADFD;
|
||||
if (!(runtime->info & SNDRV_PCM_INFO_MMAP))
|
||||
return -ENXIO;
|
||||
/* don't race with buffer reallocation in hw_params/hw_free */
|
||||
if (!atomic_inc_unless_negative(&runtime->buffer_accessing))
|
||||
return -EBUSY;
|
||||
if (runtime->state == SNDRV_PCM_STATE_OPEN) {
|
||||
err = -EBADFD;
|
||||
goto out;
|
||||
}
|
||||
if (!(runtime->info & SNDRV_PCM_INFO_MMAP)) {
|
||||
err = -ENXIO;
|
||||
goto out;
|
||||
}
|
||||
if (runtime->access == SNDRV_PCM_ACCESS_RW_INTERLEAVED ||
|
||||
runtime->access == SNDRV_PCM_ACCESS_RW_NONINTERLEAVED)
|
||||
return -EINVAL;
|
||||
runtime->access == SNDRV_PCM_ACCESS_RW_NONINTERLEAVED) {
|
||||
err = -EINVAL;
|
||||
goto out;
|
||||
}
|
||||
size = area->vm_end - area->vm_start;
|
||||
offset = area->vm_pgoff << PAGE_SHIFT;
|
||||
dma_bytes = PAGE_ALIGN(runtime->dma_bytes);
|
||||
if ((size_t)size > dma_bytes)
|
||||
return -EINVAL;
|
||||
if (offset > dma_bytes - size)
|
||||
return -EINVAL;
|
||||
if ((size_t)size > dma_bytes) {
|
||||
err = -EINVAL;
|
||||
goto out;
|
||||
}
|
||||
if (offset > dma_bytes - size) {
|
||||
err = -EINVAL;
|
||||
goto out;
|
||||
}
|
||||
|
||||
area->vm_ops = &snd_pcm_vm_ops_data;
|
||||
area->vm_private_data = substream;
|
||||
|
|
@ -4046,6 +4059,8 @@ int snd_pcm_mmap_data(struct snd_pcm_substream *substream, struct file *file,
|
|||
err = snd_pcm_lib_default_mmap(substream, area);
|
||||
if (!err)
|
||||
atomic_inc(&substream->mmap_count);
|
||||
out:
|
||||
atomic_dec(&runtime->buffer_accessing);
|
||||
return err;
|
||||
}
|
||||
EXPORT_SYMBOL(snd_pcm_mmap_data);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user