unofficial mirror of libc-alpha@sourceware.org
 help / color / mirror / Atom feed
* [PATCH 0/8] x86-64: Properly handle the length parameter [BZ# 24097]
@ 2019-01-18 20:12 H.J. Lu
  2019-01-18 20:12 ` [PATCH 1/8] x86-64 memchr/wmemchr: " H.J. Lu
                   ` (7 more replies)
  0 siblings, 8 replies; 10+ messages in thread
From: H.J. Lu @ 2019-01-18 20:12 UTC (permalink / raw)
  To: libc-alpha

On x32, the size_t parameter may be passed in the lower 32 bits of a
64-bit register with the non-zero upper 32 bits.  The string/memory
functions written in assembly can only use the lower 32 bits of a
64-bit register as length or must clear the upper 32 bits before using
the full 64-bit register for length.

This pach fixes string/memory functions written in assembly for x32.
Tested on x86-64 and x32.  On x86-64, libc.so is the same with and
withou the fix.

This fixes CVE-2019-6488.

H.J. Lu (8):
  x86-64 memchr/wmemchr: Properly handle the length parameter [BZ#
    24097]
  x86-64 memcmp/wmemcmp: Properly handle the length parameter [BZ#
    24097]
  x86-64 memcpy: Properly handle the length parameter [BZ# 24097]
  x86-64 memrchr: Properly handle the length parameter [BZ# 24097]
  x86-64 memset/wmemset: Properly handle the length parameter [BZ#
    24097]
  x86-64 strncmp family: Properly handle the length parameter [BZ#
    24097]
  x86-64 strncpy: Properly handle the length parameter [BZ# 24097]
  x86-64 strnlen/wcsnlen: Properly handle the length parameter [BZ#
    24097]

 NEWS                                          |  6 ++
 sysdeps/x86_64/memchr.S                       | 10 ++-
 sysdeps/x86_64/memrchr.S                      |  4 +-
 sysdeps/x86_64/multiarch/memchr-avx2.S        |  8 +-
 sysdeps/x86_64/multiarch/memcmp-avx2-movbe.S  |  7 +-
 sysdeps/x86_64/multiarch/memcmp-sse4.S        |  9 ++-
 sysdeps/x86_64/multiarch/memcmp-ssse3.S       |  7 +-
 sysdeps/x86_64/multiarch/memcpy-ssse3-back.S  | 17 ++--
 sysdeps/x86_64/multiarch/memcpy-ssse3.S       | 17 ++--
 .../multiarch/memmove-avx512-no-vzeroupper.S  | 16 ++--
 .../multiarch/memmove-vec-unaligned-erms.S    | 54 +++++++------
 sysdeps/x86_64/multiarch/memrchr-avx2.S       |  4 +-
 .../multiarch/memset-avx512-no-vzeroupper.S   |  6 +-
 .../multiarch/memset-vec-unaligned-erms.S     | 34 ++++----
 sysdeps/x86_64/multiarch/strcmp-avx2.S        |  6 +-
 sysdeps/x86_64/multiarch/strcmp-sse42.S       |  6 +-
 sysdeps/x86_64/multiarch/strcpy-avx2.S        |  4 +-
 .../x86_64/multiarch/strcpy-sse2-unaligned.S  |  4 +-
 sysdeps/x86_64/multiarch/strcpy-ssse3.S       |  6 +-
 sysdeps/x86_64/multiarch/strlen-avx2.S        |  9 ++-
 sysdeps/x86_64/strcmp.S                       |  6 +-
 sysdeps/x86_64/strlen.S                       | 12 +--
 sysdeps/x86_64/x32/Makefile                   | 11 +++
 sysdeps/x86_64/x32/test-size_t.h              | 35 +++++++++
 sysdeps/x86_64/x32/tst-size_t-memchr.c        | 72 +++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-memcmp.c        | 76 ++++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-memcpy.c        | 58 ++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-memrchr.c       | 57 ++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-memset.c        | 73 +++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-strncasecmp.c   | 59 ++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-strncmp.c       | 78 +++++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-strncpy.c       | 58 ++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-strnlen.c       | 72 +++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-wcsncmp.c       | 20 +++++
 sysdeps/x86_64/x32/tst-size_t-wcsnlen.c       | 20 +++++
 sysdeps/x86_64/x32/tst-size_t-wmemchr.c       | 20 +++++
 sysdeps/x86_64/x32/tst-size_t-wmemcmp.c       | 20 +++++
 sysdeps/x86_64/x32/tst-size_t-wmemset.c       | 20 +++++
 38 files changed, 905 insertions(+), 96 deletions(-)
 create mode 100644 sysdeps/x86_64/x32/test-size_t.h
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memcmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memcpy.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memrchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memset.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncasecmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncpy.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strnlen.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wcsncmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wcsnlen.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemcmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemset.c

-- 
2.20.1


^ permalink raw reply	[flat|nested] 10+ messages in thread
* [PATCH 0/8] x86-64: Properly handle the length parameter [BZ# 24097]
@ 2019-01-17 16:53 H.J. Lu
  2019-01-17 16:53 ` [PATCH 3/8] x86-64 memcpy: " H.J. Lu
  0 siblings, 1 reply; 10+ messages in thread
From: H.J. Lu @ 2019-01-17 16:53 UTC (permalink / raw)
  To: libc-alpha

On x32, the size_t parameter may be passed in the lower 32 bits of a
64-bit register with the non-zero upper 32 bits.  The string/memory
functions written in assembly can only use the lower 32 bits of a
64-bit register as length or must clear the upper 32 bits before using
the full 64-bit register for length.

This pach fixes string/memory functions written in assembly for x32.
Tested on x86-64 and x32.  On x86-64, libc.so is the same with and
withou the fix.

H.J. Lu (8):
  x86-64 memchr/wmemchr: Properly handle the length parameter [BZ#
    24097]
  x86-64 memcmp/wmemcmp: Properly handle the length parameter [BZ#
    24097]
  x86-64 memcpy: Properly handle the length parameter [BZ# 24097]
  x86-64 memrchr: Properly handle the length parameter [BZ# 24097]
  x86-64 memset/wmemset: Properly handle the length parameter [BZ#
    24097]
  x86-64 strncmp family: Properly handle the length parameter [BZ#
    24097]
  x86-64 strncpy: Properly handle the length parameter [BZ# 24097]
  x86-64 strnlen/wcsnlen: Properly handle the length parameter [BZ#
    24097]

 sysdeps/x86_64/memchr.S                       |  10 +-
 sysdeps/x86_64/memrchr.S                      |   4 +-
 sysdeps/x86_64/multiarch/memchr-avx2.S        |   8 +-
 sysdeps/x86_64/multiarch/memcmp-avx2-movbe.S  |   7 +-
 sysdeps/x86_64/multiarch/memcmp-sse4.S        |   9 +-
 sysdeps/x86_64/multiarch/memcmp-ssse3.S       |   7 +-
 sysdeps/x86_64/multiarch/memcpy-ssse3-back.S  |  17 +-
 sysdeps/x86_64/multiarch/memcpy-ssse3.S       |  17 +-
 .../multiarch/memmove-avx512-no-vzeroupper.S  |  16 +-
 .../multiarch/memmove-vec-unaligned-erms.S    |  54 +++---
 sysdeps/x86_64/multiarch/memrchr-avx2.S       |   4 +-
 .../multiarch/memset-avx512-no-vzeroupper.S   |   6 +-
 .../multiarch/memset-vec-unaligned-erms.S     |  34 ++--
 sysdeps/x86_64/multiarch/strcmp-avx2.S        |   6 +-
 sysdeps/x86_64/multiarch/strcmp-sse42.S       |   6 +-
 sysdeps/x86_64/multiarch/strcpy-avx2.S        |   4 +-
 .../x86_64/multiarch/strcpy-sse2-unaligned.S  |   4 +-
 sysdeps/x86_64/multiarch/strcpy-ssse3.S       |   6 +-
 sysdeps/x86_64/multiarch/strlen-avx2.S        |   9 +-
 sysdeps/x86_64/strcmp.S                       |   6 +-
 sysdeps/x86_64/strlen.S                       |  12 +-
 sysdeps/x86_64/x32/Makefile                   |  11 ++
 sysdeps/x86_64/x32/test-size_t.h              | 170 ++++++++++++++++++
 sysdeps/x86_64/x32/tst-size_t-memchr.c        |  72 ++++++++
 sysdeps/x86_64/x32/tst-size_t-memcmp.c        |  76 ++++++++
 sysdeps/x86_64/x32/tst-size_t-memcpy.c        |  58 ++++++
 sysdeps/x86_64/x32/tst-size_t-memrchr.c       |  57 ++++++
 sysdeps/x86_64/x32/tst-size_t-memset.c        |  73 ++++++++
 sysdeps/x86_64/x32/tst-size_t-strncasecmp.c   |  59 ++++++
 sysdeps/x86_64/x32/tst-size_t-strncmp.c       |  78 ++++++++
 sysdeps/x86_64/x32/tst-size_t-strncpy.c       |  58 ++++++
 sysdeps/x86_64/x32/tst-size_t-strnlen.c       |  72 ++++++++
 sysdeps/x86_64/x32/tst-size_t-wcsncmp.c       |  20 +++
 sysdeps/x86_64/x32/tst-size_t-wcsnlen.c       |  20 +++
 sysdeps/x86_64/x32/tst-size_t-wmemchr.c       |  20 +++
 sysdeps/x86_64/x32/tst-size_t-wmemcmp.c       |  20 +++
 sysdeps/x86_64/x32/tst-size_t-wmemset.c       |  20 +++
 37 files changed, 1034 insertions(+), 96 deletions(-)
 create mode 100644 sysdeps/x86_64/x32/test-size_t.h
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memcmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memcpy.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memrchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-memset.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncasecmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strncpy.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-strnlen.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wcsncmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wcsnlen.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemchr.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemcmp.c
 create mode 100644 sysdeps/x86_64/x32/tst-size_t-wmemset.c

-- 
2.20.1


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2019-01-18 20:14 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-01-18 20:12 [PATCH 0/8] x86-64: Properly handle the length parameter [BZ# 24097] H.J. Lu
2019-01-18 20:12 ` [PATCH 1/8] x86-64 memchr/wmemchr: " H.J. Lu
2019-01-18 20:12 ` [PATCH 2/8] x86-64 memcmp/wmemcmp: " H.J. Lu
2019-01-18 20:12 ` [PATCH 3/8] x86-64 memcpy: " H.J. Lu
2019-01-18 20:12 ` [PATCH 4/8] x86-64 memrchr: " H.J. Lu
2019-01-18 20:12 ` [PATCH 5/8] x86-64 memset/wmemset: " H.J. Lu
2019-01-18 20:12 ` [PATCH 6/8] x86-64 strncmp family: " H.J. Lu
2019-01-18 20:12 ` [PATCH 7/8] x86-64 strncpy: " H.J. Lu
2019-01-18 20:12 ` [PATCH 8/8] x86-64 strnlen/wcsnlen: " H.J. Lu
  -- strict thread matches above, loose matches on Subject: below --
2019-01-17 16:53 [PATCH 0/8] x86-64: " H.J. Lu
2019-01-17 16:53 ` [PATCH 3/8] x86-64 memcpy: " H.J. Lu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).