Skip to content

Commit d8b08f8

Browse files
ebiggersSomasundaram Krishnasamy
authored andcommitted
crypto: user - prevent operating on larval algorithms
Michal Suchanek reported [1] that running the pcrypt_aead01 test from LTP [2] in a loop and holding Ctrl-C causes a NULL dereference of alg->cra_users.next in crypto_remove_spawns(), via crypto_del_alg(). The test repeatedly uses CRYPTO_MSG_NEWALG and CRYPTO_MSG_DELALG. The crash occurs when the instance that CRYPTO_MSG_DELALG is trying to unregister isn't a real registered algorithm, but rather is a "test larval", which is a special "algorithm" added to the algorithms list while the real algorithm is still being tested. Larvals don't have initialized cra_users, so that causes the crash. Normally pcrypt_aead01 doesn't trigger this because CRYPTO_MSG_NEWALG waits for the algorithm to be tested; however, CRYPTO_MSG_NEWALG returns early when interrupted. Everything else in the "crypto user configuration" API has this same bug too, i.e. it inappropriately allows operating on larval algorithms (though it doesn't look like the other cases can cause a crash). Fix this by making crypto_alg_match() exclude larval algorithms. [1] https://lkml.kernel.org/r/[email protected] [2] https://github.com/linux-test-project/ltp/blob/20190517/testcases/kernel/crypto/pcrypt_aead01.c Reported-by: Michal Suchanek <[email protected]> Fixes: a38f790 ("crypto: Add userspace configuration API") Cc: <[email protected]> # v3.2+ Cc: Steffen Klassert <[email protected]> Signed-off-by: Eric Biggers <[email protected]> Signed-off-by: Herbert Xu <[email protected]> (cherry picked from commit 21d4120) Orabug: 30884006 Signed-off-by: Somasundaram Krishnasamy <[email protected]> Reviewed-by: John Donnelly <[email protected]>
1 parent 78842f0 commit d8b08f8

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

crypto/crypto_user.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,9 @@ static struct crypto_alg *crypto_alg_match(struct crypto_user_alg *p, int exact)
5555
list_for_each_entry(q, &crypto_alg_list, cra_list) {
5656
int match = 0;
5757

58+
if (crypto_is_larval(q))
59+
continue;
60+
5861
if ((q->cra_flags ^ p->cru_type) & p->cru_mask)
5962
continue;
6063

0 commit comments

Comments
 (0)