From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on dcvr.yhbt.net X-Spam-Level: X-Spam-ASN: AS31976 209.132.180.0/23 X-Spam-Status: No, score=-2.9 required=3.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FORGED_GMAIL_RCVD, FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS shortcircuit=no autolearn=no autolearn_force=no version=3.4.2 Received: from sourceware.org (server1.sourceware.org [209.132.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dcvr.yhbt.net (Postfix) with ESMTPS id 01D8A1F454 for ; Mon, 11 Nov 2019 10:57:03 +0000 (UTC) DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-type; q=dns; s=default; b=x2ZG q5Z01VRaF9cnvNUq8JJNMrAd+vRr26OpOqRxZWkAPbHHmXztqdinKntRWjQkKWTG 119lAz+DPwQFtOmG4hwsSazoBMBMC6SD9G1FBrcHnDfdTwtJG1KvwcEsr7eWpZTm cVO/XN0JPsVRDrmc7B6C7t8mrsw1B8ukYT+8Ml0= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-type; s=default; bh=wxT2xGvgdU OVHVLaTZhnxgsHEbc=; b=xvjo/lhOmax/ahck7uqUgyN+cCGH8OV7IUOucdX01Y vKVhNLHK1UNlCV3iS5kiOLVINDJF60YwSe5DYNtaPmc23BQKyQOh3CveURY8pZgT Nk3/9BNq4yENlhRF9JMGPLyMal+Thqsjc4AHHISQhPvVe0BgviYwIFPK1pFkYVPk Y= Received: (qmail 45059 invoked by alias); 11 Nov 2019 10:57:01 -0000 Mailing-List: contact libc-alpha-help@sourceware.org; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: libc-alpha-owner@sourceware.org Received: (qmail 45048 invoked by uid 89); 11 Nov 2019 10:57:00 -0000 Authentication-Results: sourceware.org; auth=none X-HELO: mail-qt1-f182.google.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=XXSEw84LJyw+uhHVXsGu5EDg2z/9m70f2i6i+8bIENk=; b=jc71kwQY/dfDBX9LPCqbZ/MAEURKdWQ1NPOQYQWP9q9ay/6gkigdnovErxh9VFcl2j BZoqO0wnaDhYe3qd6JZUujGgVw56Nc+/8OiG9/oSGqi+sGruXAt82uKNmMBCN7IDIb4q 975Dh3AWiUBF4txLfzF5u+gqZdSfarOvP34tEkk6BkCLywnxS7X/EsIOGyCcTwiqnNJR md/7mNfozQF32fi2CkUUEqNrC22HuxRvomrTROUI6k3ZOEi3yznm7Pj3HqK/+rYlH2+G PT9zRDIwr9b8wh4tl7nxTIBkERsn+jZYTaxVPwSTJHtmD+KrGy2VSd9H1bUhSv+YpMUJ o8rg== MIME-Version: 1.0 References: <878sovvnef.fsf@oldenburg2.str.redhat.com> In-Reply-To: <878sovvnef.fsf@oldenburg2.str.redhat.com> From: Vinay Kumar Date: Mon, 11 Nov 2019 16:26:46 +0530 Message-ID: Subject: Re: Thread stack and heap caches - CVE-2019-1010024 To: Florian Weimer Cc: libc-alpha@sourceware.org, carlos@redhat.com Content-Type: multipart/mixed; boundary="0000000000008d491805970ffd43" --0000000000008d491805970ffd43 Content-Type: text/plain; charset="UTF-8" Hi Florian, >> Does this really change the randomization? Won't the kernel map the new >> stack at a predictable address, too? Yes, every time new address is assigned as shown in the below iterations of output. Also the attached patch "aslr_glibc.patch" adds glibc configuration option "--with-aslr" to enable randomization. Compilation command: $x86_64-windriver-linux-gcc test.c -g -fpie -pie -Xlinker -rpath=/home/x86_64-tc/prefix-aslr//x86_64-windriver-linux/lib -Xlinker -I /home /x86_64-tc/prefix-aslr/x86_64-windriver-linux/lib/ld-2.30.9000.so -w -lpthread -o thread.out Output: Trial 1: ./thread.out addr: 0x7f15252bfee0 value deadbeef malloced 0x7f1520000f70 addr: 0x7f1524abeee0 value 0 malloced 0x7f1520000f70 Trial 2: ./thread.out addr: 0x7f9091640ee0 value deadbeef malloced 0x7f908c000f70 addr: 0x7f9090e3fee0 value 0 malloced 0x7f908c000f70 Trial 3: ./thread.out addr: 0x7f0d923dfee0 value deadbeef malloced 0x7f0d8c000f70 addr: 0x7f0d91bdeee0 value 0 malloced 0x7f0d8c000f70 Trial 4: ./thread.out addr: 0x7f146d97dee0 value deadbeef malloced 0x7f1468000f70 addr: 0x7f146d17cee0 value 0 malloced 0x7f1468000f70 Regards, Vinay --0000000000008d491805970ffd43 Content-Type: application/octet-stream; name="aslr_glibc.patch" Content-Disposition: attachment; filename="aslr_glibc.patch" Content-Transfer-Encoding: base64 Content-ID: X-Attachment-Id: f_k2ub8h0z0 ZGlmZiAtLWdpdCBhL2NvbmZpZy5oLmluIGIvY29uZmlnLmguaW4KaW5kZXggODI0ZGZlOC4uNjQ5 ODMzZSAxMDA2NDQKLS0tIGEvY29uZmlnLmguaW4KKysrIGIvY29uZmlnLmguaW4KQEAgLTI1NSw2 ICsyNTUsOSBAQAogLyogUG93ZXJQQzMyIHVzZXMgZmN0aWR6IGZvciBmbG9hdGluZyBwb2ludCB0 byBsb25nIGxvbmcgY29udmVyc2lvbnMuICAqLwogI2RlZmluZSBIQVZFX1BQQ19GQ1RJRFogMAog CisvKiBCdWlsZCBnbGliYyB3aXRoIEFTTFIgZW5hYmxlZCovCisjZGVmaW5lIEFTTFJfRU5BQkxF IDAKKwogLyogQnVpbGQgZ2xpYmMgd2l0aCB0dW5hYmxlcyBzdXBwb3J0LiAgKi8KICNkZWZpbmUg SEFWRV9UVU5BQkxFUyAwCiAKZGlmZiAtLWdpdCBhL2NvbmZpZ3VyZSBiL2NvbmZpZ3VyZQppbmRl eCAyZjQ0YjY2Li5mMjZkOGJkIDEwMDc1NQotLS0gYS9jb25maWd1cmUKKysrIGIvY29uZmlndXJl CkBAIC02ODgsNiArNjg4LDcgQEAgZW5hYmxlX3RpbWV6b25lX3Rvb2xzCiBleHRyYV9ub25zaGFy ZWRfY2ZsYWdzCiB1c2VfZGVmYXVsdF9saW5rCiBzeXNoZWFkZXJzCit3aXRoX2FzbHIKIGFjX2N0 X0NYWAogQ1hYRkxBR1MKIENYWApAQCAtNzYyLDYgKzc2Myw3IEBAIHdpdGhfZ2RfaW5jbHVkZQog d2l0aF9nZF9saWIKIHdpdGhfYmludXRpbHMKIHdpdGhfc2VsaW51eAord2l0aF9hc2xyCiB3aXRo X2hlYWRlcnMKIHdpdGhfZGVmYXVsdF9saW5rCiB3aXRoX25vbnNoYXJlZF9jZmxhZ3MKQEAgLTE0 ODIsNiArMTQ4NCw3IEBAIE9wdGlvbmFsIFBhY2thZ2VzOgogICAtLXdpdGgtZ2QtbGliPURJUiAg ICAgICBmaW5kIGxpYmdkIGxpYnJhcnkgZmlsZXMgaW4gRElSCiAgIC0td2l0aC1iaW51dGlscz1Q QVRIICAgIHNwZWNpZnkgbG9jYXRpb24gb2YgYmludXRpbHMgKGFzIGFuZCBsZCkKICAgLS13aXRo LXNlbGludXggICAgICAgICAgaWYgYnVpbGRpbmcgd2l0aCBTRUxpbnV4IHN1cHBvcnQKKyAgLS13 aXRoLWFzbHIgICAgICAgICAgICAgaWYgYnVpbGRpbmcgd2l0aCBBU0xSIHN1cHBvcnQKICAgLS13 aXRoLWhlYWRlcnM9UEFUSCAgICAgbG9jYXRpb24gb2Ygc3lzdGVtIGhlYWRlcnMgdG8gdXNlIChm b3IgZXhhbXBsZQogICAgICAgICAgICAgICAgICAgICAgICAgICAvdXNyL3NyYy9saW51eC9pbmNs dWRlKSBbZGVmYXVsdD1jb21waWxlciBkZWZhdWx0XQogICAtLXdpdGgtZGVmYXVsdC1saW5rICAg ICBkbyBub3QgdXNlIGV4cGxpY2l0IGxpbmtlciBzY3JpcHRzCkBAIC0zMzI0LDYgKzMzMjcsMjAg QEAgZWxzZQogZmkKIAogCisjIENoZWNrIHdoZXRoZXIgLS13aXRoLWFzbHIgd2FzIGdpdmVuLgor aWYgdGVzdCAiJHt3aXRoX2FzbHIrc2V0fSIgPSBzZXQ7IHRoZW4gOgorICB3aXRodmFsPSR3aXRo X2FzbHI7IHdpdGhfYXNscj0kd2l0aHZhbAorZWxzZQorICB3aXRoX2FzbHI9YXV0bworZmkKKwor CitpZiB0ZXN0ICIkd2l0aF9hc2xyIiA9IHllczsgdGhlbgorICAkYXNfZWNobyAiI2RlZmluZSBB U0xSX0VOQUJMRSAxIiA+PmNvbmZkZWZzLmgKKworZmkKKworCiAKICMgQ2hlY2sgd2hldGhlciAt LXdpdGgtaGVhZGVycyB3YXMgZ2l2ZW4uCiBpZiB0ZXN0ICIke3dpdGhfaGVhZGVycytzZXR9IiA9 IHNldDsgdGhlbiA6CmRpZmYgLS1naXQgYS9jb25maWd1cmUuYWMgYi9jb25maWd1cmUuYWMKaW5k ZXggZTY5Yzg4Yy4uNzQ0MjliNSAxMDA2NDQKLS0tIGEvY29uZmlndXJlLmFjCisrKyBiL2NvbmZp Z3VyZS5hYwpAQCAtMTM4LDYgKzEzOCwxNiBAQCBBQ19BUkdfV0lUSChbc2VsaW51eF0sCiAJCQkg ICBbaWYgYnVpbGRpbmcgd2l0aCBTRUxpbnV4IHN1cHBvcnRdKSwKIAkgICAgW3dpdGhfc2VsaW51 eD0kd2l0aHZhbF0sCiAJICAgIFt3aXRoX3NlbGludXg9YXV0b10pCitBQ19BUkdfV0lUSChbYXNs cl0sCisJICAgIEFDX0hFTFBfU1RSSU5HKFstLXdpdGgtYXNscl0sCisJCQkgICBbaWYgYnVpbGRp bmcgd2l0aCBBU0xSIHN1cHBvcnRdKSwKKwkgICAgW3dpdGhfYXNscj0kd2l0aHZhbF0sCisJICAg IFt3aXRoX2FzbHI9YXV0b10pCitBQ19TVUJTVCh3aXRoX2FzbHIpCitpZiB0ZXN0ICIkd2l0aF9h c2xyIiA9IHllczsgdGhlbgorICBBQ19ERUZJTkUoQVNMUl9FTkFCTEUpCitmaQorCiAKIEFDX0FS R19XSVRIKFtoZWFkZXJzXSwKIAkgICAgQUNfSEVMUF9TVFJJTkcoWy0td2l0aC1oZWFkZXJzPVBB VEhdLApkaWZmIC0tZ2l0IGEvbnB0bC9hbGxvY2F0ZXN0YWNrLmMgYi9ucHRsL2FsbG9jYXRlc3Rh Y2suYwppbmRleCA2NGE5YWU2Li4xMWU1Njg1IDEwMDY0NAotLS0gYS9ucHRsL2FsbG9jYXRlc3Rh Y2suYworKysgYi9ucHRsL2FsbG9jYXRlc3RhY2suYwpAQCAtNTQ0LDcgKzU0NCw5IEBAIGFsbG9j YXRlX3N0YWNrIChjb25zdCBzdHJ1Y3QgcHRocmVhZF9hdHRyICphdHRyLCBzdHJ1Y3QgcHRocmVh ZCAqKnBkcCwKIAogICAgICAgLyogVHJ5IHRvIGdldCBhIHN0YWNrIGZyb20gdGhlIGNhY2hlLiAg Ki8KICAgICAgIHJlcXNpemUgPSBzaXplOworICAgICAgI2lmICFBU0xSX0VOQUJMRQkKICAgICAg IHBkID0gZ2V0X2NhY2hlZF9zdGFjayAoJnNpemUsICZtZW0pOworICAgICAgI2VuZGlmIAkKICAg ICAgIGlmIChwZCA9PSBOVUxMKQogCXsKIAkgIC8qIFRvIGF2b2lkIGFsaWFzaW5nIGVmZmVjdHMg b24gYSBsYXJnZXIgc2NhbGUgdGhhbiBwYWdlcyB3ZQo= --0000000000008d491805970ffd43--