mirror of
				https://github.com/torvalds/linux.git
				synced 2025-11-04 10:40:15 +02:00 
			
		
		
		
	x86 get_unmapped_area(): use proper mmap base for bottom-up direction
When the stack is set to unlimited, the bottomup direction is used for mmap-ings but the mmap_base is not used and thus effectively renders ASLR for mmapings along with PIE useless. Cc: Michel Lespinasse <walken@google.com> Cc: Oleg Nesterov <oleg@redhat.com> Reviewed-by: Rik van Riel <riel@redhat.com> Acked-by: Ingo Molnar <mingo@kernel.org> Cc: Adrian Sendroiu <molecula2788@gmail.com> Cc: <stable@vger.kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
This commit is contained in:
		
							parent
							
								
									c7dd3392ad
								
							
						
					
					
						commit
						df54d6fa54
					
				
					 3 changed files with 3 additions and 2 deletions
				
			
		| 
						 | 
				
			
			@ -101,7 +101,7 @@ static void find_start_end(unsigned long flags, unsigned long *begin,
 | 
			
		|||
				*begin = new_begin;
 | 
			
		||||
		}
 | 
			
		||||
	} else {
 | 
			
		||||
		*begin = TASK_UNMAPPED_BASE;
 | 
			
		||||
		*begin = mmap_legacy_base();
 | 
			
		||||
		*end = TASK_SIZE;
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -98,7 +98,7 @@ static unsigned long mmap_base(void)
 | 
			
		|||
 * Bottom-up (legacy) layout on X86_32 did not support randomization, X86_64
 | 
			
		||||
 * does, but not when emulating X86_32
 | 
			
		||||
 */
 | 
			
		||||
static unsigned long mmap_legacy_base(void)
 | 
			
		||||
unsigned long mmap_legacy_base(void)
 | 
			
		||||
{
 | 
			
		||||
	if (mmap_is_ia32())
 | 
			
		||||
		return TASK_UNMAPPED_BASE;
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -314,6 +314,7 @@ struct nsproxy;
 | 
			
		|||
struct user_namespace;
 | 
			
		||||
 | 
			
		||||
#ifdef CONFIG_MMU
 | 
			
		||||
extern unsigned long mmap_legacy_base(void);
 | 
			
		||||
extern void arch_pick_mmap_layout(struct mm_struct *mm);
 | 
			
		||||
extern unsigned long
 | 
			
		||||
arch_get_unmapped_area(struct file *, unsigned long, unsigned long,
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in a new issue