[PATCH v4 0/3] Actually fix freelist pointer vs redzoning
From: Kees Cook
Date: Tue Jun 08 2021 - 14:45:10 EST
v4:
- remove redundant size check
v3: https://lore.kernel.org/lkml/20201015033712.1491731-1-keescook@xxxxxxxxxxxx
v2: https://lore.kernel.org/lkml/20201009195411.4018141-1-keescook@xxxxxxxxxxxx
v1: https://lore.kernel.org/lkml/20201008233443.3335464-1-keescook@xxxxxxxxxxxx
This fixes redzoning vs the freelist pointer (both for middle-position
and very small caches). Both are "theoretical" fixes, in that I see no
evidence of such small-sized caches actually be used in the kernel, but
that's no reason to let the bugs continue to exist, especially since
people doing local development keep tripping over it. :)
Thanks!
-Kees
Kees Cook (3):
mm/slub: Clarify verification reporting
mm/slub: Fix redzoning for small allocations
mm/slub: Actually fix freelist pointer vs redzoning
Documentation/vm/slub.rst | 10 +++++-----
mm/slab_common.c | 3 +--
mm/slub.c | 36 +++++++++++++++---------------------
3 files changed, 21 insertions(+), 28 deletions(-)
--
2.25.1