| From 7cb6138e36f39f0f9aea6327028bd67583aa5ed3 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 25 Feb 2021 17:20:53 -0800 |
| Subject: sysctl.c: fix underflow value setting risk in vm_table |
| |
| From: Lin Feng <linf@wangsu.com> |
| |
| [ Upstream commit 3b3376f222e3ab58367d9dd405cafd09d5e37b7c ] |
| |
| Apart from subsystem specific .proc_handler handler, all ctl_tables with |
| extra1 and extra2 members set should use proc_dointvec_minmax instead of |
| proc_dointvec, or the limit set in extra* never work and potentially echo |
| underflow values(negative numbers) is likely make system unstable. |
| |
| Especially vfs_cache_pressure and zone_reclaim_mode, -1 is apparently not |
| a valid value, but we can set to them. And then kernel may crash. |
| |
| # echo -1 > /proc/sys/vm/vfs_cache_pressure |
| |
| Link: https://lkml.kernel.org/r/20201223105535.2875-1-linf@wangsu.com |
| Signed-off-by: Lin Feng <linf@wangsu.com> |
| Cc: Alexey Dobriyan <adobriyan@gmail.com> |
| Cc: "Eric W. Biederman" <ebiederm@xmission.com> |
| Signed-off-by: Andrew Morton <akpm@linux-foundation.org> |
| Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| kernel/sysctl.c | 8 ++++---- |
| 1 file changed, 4 insertions(+), 4 deletions(-) |
| |
| diff --git a/kernel/sysctl.c b/kernel/sysctl.c |
| index 70665934d53e..eae6a078619f 100644 |
| --- a/kernel/sysctl.c |
| +++ b/kernel/sysctl.c |
| @@ -1563,7 +1563,7 @@ static struct ctl_table vm_table[] = { |
| .data = &block_dump, |
| .maxlen = sizeof(block_dump), |
| .mode = 0644, |
| - .proc_handler = proc_dointvec, |
| + .proc_handler = proc_dointvec_minmax, |
| .extra1 = SYSCTL_ZERO, |
| }, |
| { |
| @@ -1571,7 +1571,7 @@ static struct ctl_table vm_table[] = { |
| .data = &sysctl_vfs_cache_pressure, |
| .maxlen = sizeof(sysctl_vfs_cache_pressure), |
| .mode = 0644, |
| - .proc_handler = proc_dointvec, |
| + .proc_handler = proc_dointvec_minmax, |
| .extra1 = SYSCTL_ZERO, |
| }, |
| #if defined(HAVE_ARCH_PICK_MMAP_LAYOUT) || \ |
| @@ -1581,7 +1581,7 @@ static struct ctl_table vm_table[] = { |
| .data = &sysctl_legacy_va_layout, |
| .maxlen = sizeof(sysctl_legacy_va_layout), |
| .mode = 0644, |
| - .proc_handler = proc_dointvec, |
| + .proc_handler = proc_dointvec_minmax, |
| .extra1 = SYSCTL_ZERO, |
| }, |
| #endif |
| @@ -1591,7 +1591,7 @@ static struct ctl_table vm_table[] = { |
| .data = &node_reclaim_mode, |
| .maxlen = sizeof(node_reclaim_mode), |
| .mode = 0644, |
| - .proc_handler = proc_dointvec, |
| + .proc_handler = proc_dointvec_minmax, |
| .extra1 = SYSCTL_ZERO, |
| }, |
| { |
| -- |
| 2.30.1 |
| |