Skip to content

[fips-8.6] arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array - #270

Merged
bmastbergen merged 1 commit into
fips-8-compliant/4.18.0-553.16.1from
bmastbergen_fips-8-compliant/4.18.0-553.16.1/VULN-54128
May 19, 2025
Merged

[fips-8.6] arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array#270
bmastbergen merged 1 commit into
fips-8-compliant/4.18.0-553.16.1from
bmastbergen_fips-8-compliant/4.18.0-553.16.1/VULN-54128

Conversation

@bmastbergen

Copy link
Copy Markdown
Collaborator

jira VULN-54128
cve CVE-2025-21785

This is an arm64 specific change, which I don't know that we strictly care about in fips branches. But I don't think it hurts to be in there. Since there isn't a current aarch64 fips-8.6 kernel to test against I only ran kselftest against the source built kernel under test. See this PR for lts-8.6 for the same change to see more test results: #232

commit-author Radu Rendec <rrendec@redhat.com>
commit 875d742cf5327c93cba1f11e12b08d3cce7a88d2
The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).
Fixes: 5d425c186537 ("arm64: kernel: add support for cpu cache information")
Signed-off-by: Radu Rendec <rrendec@redhat.com>
Link: https://lore.kernel.org/r/20250206174420.2178724-1-rrendec@redhat.com
Signed-off-by: Will Deacon <will@kernel.org>
(cherry picked from commit 875d742cf5327c93cba1f11e12b08d3cce7a88d2)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>

Build Log

/home/brett/kernel-src-tree
no .config file found, moving on
[TIMER]{MRPROPER}: 0s
aarch64 architecture detected, copying config
'configs/kernel-aarch64.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284"
Making olddefconfig
HOSTCC scripts/basic/fixdep
HOSTCC scripts/kconfig/conf.o
YACC scripts/kconfig/zconf.tab.c
LEX scripts/kconfig/zconf.lex.c
HOSTCC scripts/kconfig/zconf.tab.o
HOSTLD scripts/kconfig/conf
scripts/kconfig/conf --olddefconfig Kconfig
#
# configuration written to .config
#
Starting Build
scripts/kconfig/conf --syncconfig Kconfig
UPD include/config/kernel.release
WRAP arch/arm64/include/generated/uapi/asm/errno.h
WRAP arch/arm64/include/generated/uapi/asm/ioctl.h
WRAP arch/arm64/include/generated/uapi/asm/ipcbuf.h
WRAP arch/arm64/include/generated/uapi/asm/mman.h
WRAP arch/arm64/include/generated/uapi/asm/msgbuf.h
WRAP arch/arm64/include/generated/uapi/asm/kvm_para.h
WRAP arch/arm64/include/generated/uapi/asm/ioctls.h
WRAP arch/arm64/include/generated/uapi/asm/poll.h
WRAP arch/arm64/include/generated/uapi/asm/resource.h
WRAP arch/arm64/include/generated/uapi/asm/sembuf.h
WRAP arch/arm64/include/generated/uapi/asm/shmbuf.h
WRAP arch/arm64/include/generated/uapi/asm/socket.h
WRAP arch/arm64/include/generated/uapi/asm/sockios.h
WRAP arch/arm64/include/generated/uapi/asm/swab.h
WRAP arch/arm64/include/generated/uapi/asm/termbits.h
WRAP arch/arm64/include/generated/uapi/asm/termios.h
WRAP arch/arm64/include/generated/uapi/asm/siginfo.h
WRAP arch/arm64/include/generated/uapi/asm/types.h
UPD include/generated/uapi/linux/version.h
UPD include/generated/utsrelease.h
DESCEND bpf/resolve_btfids
MKDIR /home/brett/kernel-src-tree/tools/bpf/resolve_btfids//libsubcmd
MKDIR /home/brett/kernel-src-tree/tools/bpf/resolve_btfids//libbpf
HOSTCC /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/fixdep.o
GEN /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/bpf_helper_defs.h
MKDIR /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/
CC /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/libbpf.o
HOSTLD /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/fixdep-in.o
MKDIR /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/
LINK /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/fixdep
CC /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/nlattr.o
CC /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/btf.o
CC /home/brett/kernel-src-tree/tools/bpf/resolve_btfids/libbpf/staticobjs/libbpf_errno.o
[SNIP]
INSTALL net/sched/sch_pie.ko
INSTALL net/sched/sch_plug.ko
INSTALL net/sched/sch_prio.ko
INSTALL net/sched/sch_qfq.ko
INSTALL net/sched/sch_red.ko
INSTALL net/sched/sch_sfb.ko
INSTALL net/sched/sch_sfq.ko
INSTALL net/sched/sch_tbf.ko
INSTALL net/sched/sch_teql.ko
INSTALL net/sctp/sctp.ko
INSTALL net/sctp/sctp_diag.ko
INSTALL net/sunrpc/auth_gss/auth_rpcgss.ko
INSTALL net/sunrpc/auth_gss/rpcsec_gss_krb5.ko
INSTALL net/sunrpc/sunrpc.ko
INSTALL net/sunrpc/xprtrdma/rpcrdma.ko
INSTALL net/tipc/diag.ko
INSTALL net/tipc/tipc.ko
INSTALL net/tls/tls.ko
INSTALL net/unix/unix_diag.ko
INSTALL net/vmw_vsock/hv_sock.ko
INSTALL net/vmw_vsock/vmw_vsock_virtio_transport.ko
INSTALL net/vmw_vsock/vmw_vsock_virtio_transport_common.ko
INSTALL net/vmw_vsock/vsock.ko
INSTALL net/vmw_vsock/vsock_diag.ko
INSTALL net/vmw_vsock/vsock_loopback.ko
INSTALL net/xdp/xsk_diag.ko
INSTALL net/xfrm/xfrm_interface.ko
INSTALL net/xfrm/xfrm_ipcomp.ko
INSTALL security/keys/encrypted-keys/encrypted-keys.ko
INSTALL security/keys/trusted-keys/trusted.ko
INSTALL sound/soundcore.ko
DEPMOD 4.18.0-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284+
[TIMER]{MODULES}: 198s
Making Install
/bin/sh ./arch/arm64/boot/install.sh 4.18.0-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284+ \
arch/arm64/boot/Image System.map "/boot"
[TIMER]{INSTALL}: 1353s
Checking kABI
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-4.18.0-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284+ and Index to 0
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 0s
[TIMER]{BUILD}: 25164s
[TIMER]{MODULES}: 198s
[TIMER]{INSTALL}: 1353s
[TIMER]{TOTAL} 26970s
Rebooting in 10 seconds

Testing

kselftests were run against the built kernel under test only

selftest-4.18.0-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284+.log

brett@lycia ~/ciq/vuln-54128 % grep ^ok selftest-4.18.0-b_f-8-c_4.18.0-553.16.1_VULN-54128-6ac224458284+.log | wc -l
167
brett@lycia ~/ciq/vuln-54128 %

jira VULN-54128
cve CVE-2025-21785
commit-author Radu Rendec <rrendec@redhat.com>
commit 875d742
The loop that detects/populates cache information already has a bounds
check on the array size but does not account for cache levels with
separate data/instructions cache. Fix this by incrementing the index
for any populated leaf (instead of any populated level).
Fixes: 5d425c1 ("arm64: kernel: add support for cpu cache information")
Signed-off-by: Radu Rendec <rrendec@redhat.com>
Link: https://lore.kernel.org/r/20250206174420.2178724-1-rrendec@redhat.com
Signed-off-by: Will Deacon <will@kernel.org>
(cherry picked from commit 875d742)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
@PlaidCat

PlaidCat commented May 16, 2025

Copy link
Copy Markdown
Collaborator

aarch64 currently doesn't ship for fips kernels but should that ever change its in place

@PlaidCatPlaidCat left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@thefossguy-ciqthefossguy-ciq left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚤

@bmastbergen
bmastbergen merged commit f4e668d into fips-8-compliant/4.18.0-553.16.1May 19, 2025
@bmastbergen
bmastbergen deleted the bmastbergen_fips-8-compliant/4.18.0-553.16.1/VULN-54128 branch May 19, 2025 13:08
bmastbergen pushed a commit to bmastbergen/kernel-src-tree that referenced this pull request Aug 29, 2025
jira LE-1907
Rebuild_History Non-Buildable kernel-5.14.0-427.18.1.el9_4
commit-author Daniel Borkmann <daniel@iogearbox.net>
commit f9b0879
Add a new test case which performs double query of the bpf_mprog through
libbpf API, but also via raw bpf(2) syscall. This is testing to gather
first the count and then in a subsequent probe the full information with
the program array without clearing passed structs in between.
# ./vmtest.sh -- ./test_progs -t tc_opts
[...]
./test_progs -t tc_opts
[ 1.398818] tsc: Refined TSC clocksource calibration: 3407.999 MHz
[ 1.400263] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x311fd336761, max_idle_ns: 440795243819 ns
[ 1.402734] clocksource: Switched to clocksource tsc
[ 1.426639] bpf_testmod: loading out-of-tree module taints kernel.
[ 1.428112] bpf_testmod: module verification failed: signature and/or required key missing - tainting kernel
ctrliq#252 tc_opts_after:OK
ctrliq#253 tc_opts_append:OK
ctrliq#254 tc_opts_basic:OK
ctrliq#255 tc_opts_before:OK
ctrliq#256 tc_opts_chain_classic:OK
ctrliq#257 tc_opts_chain_mixed:OK
ctrliq#258 tc_opts_delete_empty:OK
ctrliq#259 tc_opts_demixed:OK
ctrliq#260 tc_opts_detach:OK
ctrliq#261 tc_opts_detach_after:OK
ctrliq#262 tc_opts_detach_before:OK
ctrliq#263 tc_opts_dev_cleanup:OK
ctrliq#264 tc_opts_invalid:OK
ctrliq#265 tc_opts_max:OK
ctrliq#266 tc_opts_mixed:OK
ctrliq#267 tc_opts_prepend:OK
ctrliq#268 tc_opts_query:OK <--- (new test)
ctrliq#269 tc_opts_replace:OK
ctrliq#270 tc_opts_revision:OK
Summary: 19/0 PASSED, 0 SKIPPED, 0 FAILED
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20231006220655.1653-4-daniel@iogearbox.net
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
(cherry picked from commit f9b0879)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
bmastbergen pushed a commit to bmastbergen/kernel-src-tree that referenced this pull request Aug 29, 2025
jira LE-1907
Rebuild_History Non-Buildable kernel-5.14.0-427.18.1.el9_4
commit-author Daniel Borkmann <daniel@iogearbox.net>
commit 685446b
Add a new test case to query on an empty bpf_mprog and pass the revision
directly into expected_revision for attachment to assert that this does
succeed.
./test_progs -t tc_opts
[ 1.406778] tsc: Refined TSC clocksource calibration: 3407.990 MHz
[ 1.408863] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x311fcaf6eb0, max_idle_ns: 440795321766 ns
[ 1.412419] clocksource: Switched to clocksource tsc
[ 1.428671] bpf_testmod: loading out-of-tree module taints kernel.
[ 1.430260] bpf_testmod: module verification failed: signature and/or required key missing - tainting kernel
ctrliq#252 tc_opts_after:OK
ctrliq#253 tc_opts_append:OK
ctrliq#254 tc_opts_basic:OK
ctrliq#255 tc_opts_before:OK
ctrliq#256 tc_opts_chain_classic:OK
ctrliq#257 tc_opts_chain_mixed:OK
ctrliq#258 tc_opts_delete_empty:OK
ctrliq#259 tc_opts_demixed:OK
ctrliq#260 tc_opts_detach:OK
ctrliq#261 tc_opts_detach_after:OK
ctrliq#262 tc_opts_detach_before:OK
ctrliq#263 tc_opts_dev_cleanup:OK
ctrliq#264 tc_opts_invalid:OK
ctrliq#265 tc_opts_max:OK
ctrliq#266 tc_opts_mixed:OK
ctrliq#267 tc_opts_prepend:OK
ctrliq#268 tc_opts_query:OK
ctrliq#269 tc_opts_query_attach:OK <--- (new test)
ctrliq#270 tc_opts_replace:OK
ctrliq#271 tc_opts_revision:OK
Summary: 20/0 PASSED, 0 SKIPPED, 0 FAILED
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20231006220655.1653-6-daniel@iogearbox.net
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
(cherry picked from commit 685446b)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
bmastbergen pushed a commit to bmastbergen/kernel-src-tree that referenced this pull request Aug 29, 2025
jira LE-1907
Rebuild_History Non-Buildable kernel-5.14.0-427.18.1.el9_4
commit-author Daniel Borkmann <daniel@iogearbox.net>
commit 2451630
Add several new test cases which assert corner cases on the mprog query
mechanism, for example, around passing in a too small or a larger array
than the current count.
./test_progs -t tc_opts
ctrliq#252 tc_opts_after:OK
ctrliq#253 tc_opts_append:OK
ctrliq#254 tc_opts_basic:OK
ctrliq#255 tc_opts_before:OK
ctrliq#256 tc_opts_chain_classic:OK
ctrliq#257 tc_opts_chain_mixed:OK
ctrliq#258 tc_opts_delete_empty:OK
ctrliq#259 tc_opts_demixed:OK
ctrliq#260 tc_opts_detach:OK
ctrliq#261 tc_opts_detach_after:OK
ctrliq#262 tc_opts_detach_before:OK
ctrliq#263 tc_opts_dev_cleanup:OK
ctrliq#264 tc_opts_invalid:OK
ctrliq#265 tc_opts_max:OK
ctrliq#266 tc_opts_mixed:OK
ctrliq#267 tc_opts_prepend:OK
ctrliq#268 tc_opts_query:OK
ctrliq#269 tc_opts_query_attach:OK
ctrliq#270 tc_opts_replace:OK
ctrliq#271 tc_opts_revision:OK
Summary: 20/0 PASSED, 0 SKIPPED, 0 FAILED
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Alan Maguire <alan.maguire@oracle.com>
Link: https://lore.kernel.org/bpf/20231017081728.24769-1-daniel@iogearbox.net
(cherry picked from commit 2451630)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bmastbergen@PlaidCat@kerneltoast@thefossguy-ciq