Message ID | 20221216233355.542197-2-robdclark@gmail.com |
---|---|
State | New |
Headers |
Return-Path: <linux-kernel-owner@vger.kernel.org> Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:e747:0:0:0:0:0 with SMTP id c7csp1256649wrn; Fri, 16 Dec 2022 15:35:43 -0800 (PST) X-Google-Smtp-Source: AMrXdXvzBINyTG5RzXFSXfCrj20VkvpKRLtBFBdfm4JZKwlQ3oM3XHxijM1unL6p0D3w9BgHcxp9 X-Received: by 2002:a17:902:e549:b0:18f:9282:d8b0 with SMTP id n9-20020a170902e54900b0018f9282d8b0mr158622plf.53.1671233742810; Fri, 16 Dec 2022 15:35:42 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1671233742; cv=none; d=google.com; s=arc-20160816; b=fLij6NlTS9VufLYM+DwaN+b+1xX0AHjlrbwUF6feWihjNnzKS4/AfiY1sGkit733Gu dmVnqAYwwZ/dn67Z7qNUqvaGAM9pAXo/yhMJppEuPIIYhhgcquq6z4WeWifKAzgDRVif mtzuJXLipNIQvNpFQp7L/4W2Eq5ag54t0QLEz0puDDlnrbJ3pNmPlsfIpNl2GxvTyfIf rwdBg5QCCe5mhIykpxisFmaucUJaYwTj4yYKJ4t0KwPIyX/Y+cBHXRmL1zyJADcK44Z2 pv5dhmao+Ibvl9rdQ9+xfSVvglsNy0eljIrMjxJXollaZzk47Az80qfjo8/KVXUonZ54 t2zw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=wfjZR0CL1te6hYjGQ5Dgru9uZsEh0pXQEs7OK+nQBYw=; b=JjWqpHjwewNi8RcaZSXPMiSOdWWFierdiFbYfnbZV6vujySOEKH2fLVRcbem/kwD7P T7eIkV6T4wTKbxObNIGPUTh8aIXXduSkHw0Ukjqj9w7r2CVqkt62FYTvqHNwwVikLMMK MfESYC/tzvpNowyZqhRW8BcZ/Cmjlv+STMECoYIZDTBbUyoSWaaswUcQFWvKUFSidIAj NNOFzEGxDX5Meb8kEqw3XnqgQa1iv7jc0iiCh3AmIOR8PkESECBcoHeIsoOOgOQAolTv FXaYT6jaMAfg9Pnfiwz6P/TSABxxKoZvYIzzajT7hSyZz9XgGdTj7wNHMdx4TKZD7FsM IRrw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=MEAPdrhZ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id b184-20020a6367c1000000b0046b127a1e8bsi3883076pgc.488.2022.12.16.15.35.29; Fri, 16 Dec 2022 15:35:42 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=MEAPdrhZ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229820AbiLPXd6 (ORCPT <rfc822;jeantsuru.cumc.mandola@gmail.com> + 99 others); Fri, 16 Dec 2022 18:33:58 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:55694 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229562AbiLPXd4 (ORCPT <rfc822;linux-kernel@vger.kernel.org>); Fri, 16 Dec 2022 18:33:56 -0500 Received: from mail-pl1-x634.google.com (mail-pl1-x634.google.com [IPv6:2607:f8b0:4864:20::634]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 693D32BF for <linux-kernel@vger.kernel.org>; Fri, 16 Dec 2022 15:33:55 -0800 (PST) Received: by mail-pl1-x634.google.com with SMTP id 17so3838426pll.0 for <linux-kernel@vger.kernel.org>; Fri, 16 Dec 2022 15:33:55 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=wfjZR0CL1te6hYjGQ5Dgru9uZsEh0pXQEs7OK+nQBYw=; b=MEAPdrhZCgMx9z1Z6Jn2EYHyIXxjfM1YSxkXyqhSTc2jPmkC1c0uWfXBTsUYHE4PtP h8rVGbHesBKlT+CU8fc6gdoh+eOabsO2dVBJGr+mVHhCuUmi6DwypQm/9vV1MI1fcg1D 5/Yf8XKQKp8JDF1kx0kdS89aVofVbDMcDrnd3M+E0O8FW5mqg3NBwMpmq92xGyZeL7yA dYhh8ayAcrmYr90vQ5arscaU13bsjieP09SmQliZrPvFAVWLqFwfXbCVU6Fl1I09FxNL 01/YSveCtv21TrKwk4tV+8bE8YqKj4uQoT9ueZf8XPZpLeFHtkswnov/hR++CjriaVDq WNZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=wfjZR0CL1te6hYjGQ5Dgru9uZsEh0pXQEs7OK+nQBYw=; b=XdOXuxDtTc7QzeBmk5l5g29O4MWMjWFe5hyXozXHkIgNbgMEujXnFjefWAIWcBhH5y 9Q2QHYoxdy2s33kYRREJMIICEM6YH29i66oNO/VxvpCgpArNTGYSWukMJ3ryscXQzHm/ opi51gbP+Nj0cfsEuLQw1R5ptVkF/OuhxcXIwAYP2SObay9ScQ9gidTr5aBH31D+/yh7 ROZ0RADDJL8rOXl+CBiVJ0Fz1s9Pqvrnwg+FRe+GE4l9vhxxG60/ud9TFq2N/l0l3zd5 i1UyPyhPvbPbAVW61RnYQJK/rrmjIypK7W3WrqkWJ7uvr0cvOIrRvUzNxkcUK1IY82r3 XkoA== X-Gm-Message-State: AFqh2krWSIkTboONoCtvlSvlq+nmxRMvE0kr6k+uKS7ZFYZxsDB7KQQ3 ojuXIUJrZWT0WS7tB6NYadU= X-Received: by 2002:a17:90a:6744:b0:219:1d62:9e05 with SMTP id c4-20020a17090a674400b002191d629e05mr164074pjm.34.1671233634873; Fri, 16 Dec 2022 15:33:54 -0800 (PST) Received: from localhost ([2a00:79e1:abd:4a00:2703:3c72:eb1a:cffd]) by smtp.gmail.com with ESMTPSA id 64-20020a630743000000b0047781f8ac17sm1976000pgh.77.2022.12.16.15.33.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Dec 2022 15:33:54 -0800 (PST) From: Rob Clark <robdclark@gmail.com> To: dri-devel@lists.freedesktop.org Cc: Rob Clark <robdclark@chromium.org>, David Airlie <airlied@redhat.com>, Gerd Hoffmann <kraxel@redhat.com>, Gurchetan Singh <gurchetansingh@chromium.org>, Chia-I Wu <olvaffe@gmail.com>, Daniel Vetter <daniel@ffwll.ch>, virtualization@lists.linux-foundation.org (open list:VIRTIO GPU DRIVER), linux-kernel@vger.kernel.org (open list) Subject: [PATCH] drm/virtio: Fix GEM handle creation UAF Date: Fri, 16 Dec 2022 15:33:55 -0800 Message-Id: <20221216233355.542197-2-robdclark@gmail.com> X-Mailer: git-send-email 2.38.1 In-Reply-To: <20221216233355.542197-1-robdclark@gmail.com> References: <20221216233355.542197-1-robdclark@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: <linux-kernel.vger.kernel.org> X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1752415592858142145?= X-GMAIL-MSGID: =?utf-8?q?1752415592858142145?= |
Series |
drm/virtio: Fix GEM handle creation UAF
|
|
Commit Message
Rob Clark
Dec. 16, 2022, 11:33 p.m. UTC
From: Rob Clark <robdclark@chromium.org> Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done *after* we are done dereferencing the object. Signed-off-by: Rob Clark <robdclark@chromium.org> --- drivers/gpu/drm/virtio/virtgpu_ioctl.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-)
Comments
On Fri, Dec 16, 2022 at 3:33 PM Rob Clark <robdclark@gmail.com> wrote: > > From: Rob Clark <robdclark@chromium.org> > > Userspace can guess the handle value and try to race GEM object creation > with handle close, resulting in a use-after-free if we dereference the > object after dropping the handle's reference. For that reason, dropping > the handle's reference must be done *after* we are done dereferencing > the object. > > Signed-off-by: Rob Clark <robdclark@chromium.org> Reviewed-by: Chia-I Wu <olvaffe@gmail.com>
On 12/17/22 02:33, Rob Clark wrote: > From: Rob Clark <robdclark@chromium.org> > > Userspace can guess the handle value and try to race GEM object creation > with handle close, resulting in a use-after-free if we dereference the > object after dropping the handle's reference. For that reason, dropping > the handle's reference must be done *after* we are done dereferencing > the object. > > Signed-off-by: Rob Clark <robdclark@chromium.org> > --- > drivers/gpu/drm/virtio/virtgpu_ioctl.c | 19 +++++++++++++++++-- > 1 file changed, 17 insertions(+), 2 deletions(-) Added fixes/stable tags and applied this virtio-gpu patch to misc-fixes. The Panfrost patch is untouched.
On Mon, Jan 9, 2023 at 3:28 PM Dmitry Osipenko <dmitry.osipenko@collabora.com> wrote: > > On 12/17/22 02:33, Rob Clark wrote: > > From: Rob Clark <robdclark@chromium.org> > > > > Userspace can guess the handle value and try to race GEM object creation > > with handle close, resulting in a use-after-free if we dereference the > > object after dropping the handle's reference. For that reason, dropping > > the handle's reference must be done *after* we are done dereferencing > > the object. > > > > Signed-off-by: Rob Clark <robdclark@chromium.org> > > --- > > drivers/gpu/drm/virtio/virtgpu_ioctl.c | 19 +++++++++++++++++-- > > 1 file changed, 17 insertions(+), 2 deletions(-) > > Added fixes/stable tags and applied this virtio-gpu patch to misc-fixes. > The Panfrost patch is untouched. Thanks.. the panfrost patch was not intended to be part of the same series (but apparently that is what happens when I send them at the same time), and was superceded by a patch from Steven Price (commit 4217c6ac8174 ("drm/panfrost: Fix GEM handle creation ref-counting") already applied to misc-fixes BR, -R
On 1/10/23 04:47, Rob Clark wrote: > On Mon, Jan 9, 2023 at 3:28 PM Dmitry Osipenko > <dmitry.osipenko@collabora.com> wrote: >> >> On 12/17/22 02:33, Rob Clark wrote: >>> From: Rob Clark <robdclark@chromium.org> >>> >>> Userspace can guess the handle value and try to race GEM object creation >>> with handle close, resulting in a use-after-free if we dereference the >>> object after dropping the handle's reference. For that reason, dropping >>> the handle's reference must be done *after* we are done dereferencing >>> the object. >>> >>> Signed-off-by: Rob Clark <robdclark@chromium.org> >>> --- >>> drivers/gpu/drm/virtio/virtgpu_ioctl.c | 19 +++++++++++++++++-- >>> 1 file changed, 17 insertions(+), 2 deletions(-) >> >> Added fixes/stable tags and applied this virtio-gpu patch to misc-fixes. >> The Panfrost patch is untouched. > > Thanks.. the panfrost patch was not intended to be part of the same > series (but apparently that is what happens when I send them at the > same time), and was superceded by a patch from Steven Price (commit > 4217c6ac8174 ("drm/panfrost: Fix GEM handle creation ref-counting") > already applied to misc-fixes Okay, I wanted to make clear what has been applied.
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c index a5cccccb4998..f1c55c1630ca 100644 --- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c +++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c @@ -366,10 +366,18 @@ static int virtio_gpu_resource_create_ioctl(struct drm_device *dev, void *data, drm_gem_object_release(obj); return ret; } - drm_gem_object_put(obj); rc->res_handle = qobj->hw_res_handle; /* similiar to a VM address */ rc->bo_handle = handle; + + /* + * The handle owns the reference now. But we must drop our + * remaining reference *after* we no longer need to dereference + * the obj. Otherwise userspace could guess the handle and + * race closing it from another thread. + */ + drm_gem_object_put(obj); + return 0; } @@ -731,11 +739,18 @@ static int virtio_gpu_resource_create_blob_ioctl(struct drm_device *dev, drm_gem_object_release(obj); return ret; } - drm_gem_object_put(obj); rc_blob->res_handle = bo->hw_res_handle; rc_blob->bo_handle = handle; + /* + * The handle owns the reference now. But we must drop our + * remaining reference *after* we no longer need to dereference + * the obj. Otherwise userspace could guess the handle and + * race closing it from another thread. + */ + drm_gem_object_put(obj); + return 0; }