diff options
author | Avi Kivity <avi@qumranet.com> | 2010-01-10 09:28:09 -0500 |
---|---|---|
committer | Linus Torvalds <torvalds@linux-foundation.org> | 2010-01-11 12:45:37 -0500 |
commit | a29815a333c6c6e677294bbe5958e771d0aad3fd (patch) | |
tree | 589a782f1992a7da55469379688deaa9f355b779 /arch | |
parent | c0f607c608ba889db5250235ba620f818aa44a4d (diff) |
core, x86: make LIST_POISON less deadly
The list macros use LIST_POISON1 and LIST_POISON2 as undereferencable
pointers in order to trap erronous use of freed list_heads. Unfortunately
userspace can arrange for those pointers to actually be dereferencable,
potentially turning an oops to an expolit.
To avoid this allow architectures (currently x86_64 only) to override
the default values for these pointers with truly-undereferencable values.
This is easy on x86_64 as the virtual address space is large and contains
areas that cannot be mapped.
Other 64-bit architectures will likely find similar unmapped ranges.
[ingo: switch to 0xdead000000000000 as the unmapped area]
[ingo: add comments, cleanup]
[jaswinder: eliminate sparse warnings]
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jaswinder Singh Rajput <jaswinderrajput@gmail.com>
Signed-off-by: Ingo Molnar <mingo@elte.hu>
Signed-off-by: Avi Kivity <avi@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Diffstat (limited to 'arch')
-rw-r--r-- | arch/x86/Kconfig | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index 6bf1f1ac478c..cbcbfdee3ee0 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig | |||
@@ -1247,6 +1247,11 @@ config ARCH_MEMORY_PROBE | |||
1247 | def_bool X86_64 | 1247 | def_bool X86_64 |
1248 | depends on MEMORY_HOTPLUG | 1248 | depends on MEMORY_HOTPLUG |
1249 | 1249 | ||
1250 | config ILLEGAL_POINTER_VALUE | ||
1251 | hex | ||
1252 | default 0 if X86_32 | ||
1253 | default 0xdead000000000000 if X86_64 | ||
1254 | |||
1250 | source "mm/Kconfig" | 1255 | source "mm/Kconfig" |
1251 | 1256 | ||
1252 | config HIGHPTE | 1257 | config HIGHPTE |