Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

fuse: Initialize beyond-EOF page contents before setting uptodate

fuse_notify_store(), unlike fuse_do_readpage(), does not enable page
zeroing (because it can be used to change partial page contents).

So fuse_notify_store() must be more careful to fully initialize page
contents (including parts of the page that are beyond end-of-file)
before marking the page uptodate.

The current code can leave beyond-EOF page contents uninitialized, which
makes these uninitialized page contents visible to userspace via mmap().

This is an information leak, but only affects systems which do not
enable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the
corresponding kernel command line parameter).

Link: https://bugs.chromium.org/p/project-zero/issues/detail?id=2574
Cc: stable@kernel.org
Fixes: a1d75f258230 ("fuse: add store request")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

authored by

Jann Horn and committed by
Linus Torvalds
3c0da3d1 c3f2d783

+4 -2
+4 -2
fs/fuse/dev.c
··· 1618 1618 1619 1619 this_num = min_t(unsigned, num, PAGE_SIZE - offset); 1620 1620 err = fuse_copy_page(cs, &page, offset, this_num, 0); 1621 - if (!err && offset == 0 && 1622 - (this_num == PAGE_SIZE || file_size == end)) 1621 + if (!PageUptodate(page) && !err && offset == 0 && 1622 + (this_num == PAGE_SIZE || file_size == end)) { 1623 + zero_user_segment(page, this_num, PAGE_SIZE); 1623 1624 SetPageUptodate(page); 1625 + } 1624 1626 unlock_page(page); 1625 1627 put_page(page); 1626 1628