[PATCH] Fix i386 memmove issue [BZ #22644]

Florian Weimer fweimer@redhat.com
Mon Mar 19 13:17:00 GMT 2018


On 03/19/2018 02:11 PM, Andreas Schwab wrote:
> On Mär 19 2018, Andrew Senkevich<andrew.n.senkevich@gmail.com>  wrote:
> 
>> +static void
>> +do_test2 (void)
>> +{
>> +  uint32_t num = 0x20000000;
>> +  uint32_t * large_buf;
>> +
>> +  large_buf = mmap ((void*)0x70000000, num, PROT_READ | PROT_WRITE,
>> +     MAP_PRIVATE | MAP_ANON | MAP_FIXED, -1, 0);
> Since you are using MAP_FIXED this may overwrite an existing mapping.

Leading to a hard-to-debug crash, maybe sporadically due to ASLR.  Yes, 
I have this concern as well.

There was a long, long Linux thread about a non-overriding MAP_FIXED 
variant, but as far as I can see, this has not been merged.  Maybe it 
would have helped here.

Is it very difficult to split out this test into a separate test file? 
Then link the whole thing statically, as non-PIE, and keep using 
MAP_FIXED.  This should make it quite likely that you don't override 
anything valuable.

Or you could parse /proc/self/maps to make sure that you don't override 
an existing mapping.  Yuck.

Thanks,
Florian



More information about the Libc-alpha mailing list