【微信群技术讨论】BUG: KASan: user-memory-access on address 00000000da3f9000
本文是原「蜗窝讨论区」的历史存档(2017-08-02),来自版块「Linux kernel技术问答」,共 1 帖。讨论区已停止服务,此处仅供查阅。
问题描述: 打开KASAN监测kernel内存, 发现会出现BUG: KASan: user-memory-access on address 00000000da3f9000, 从trace里面分析copy_from_user传入了一个不在user stack 里面地址. 比如: user space: int nTest; ioctl(xxx, xxx, &nTest);
kernel space: int xxx_IOCt(struct file filp, unsigned int u32Cmd, unsigned long u32Arg) { .... if(copy_from_user(xxx, (int __user )arg, sizeof(int))) //这里的arg即nTest的地址不在stack里面. { return -EFAULT; } }
Debug发现: 局部变量的地址没有溢出但不在stack的VMA范围, 而stack和局部变量的地址所在vma都有执行权限 比如: nTest的地址是da3f9050, cat /proc/{pid}/maps 看到 da3f9000-dabf8000 rwxp 00000000 00:00 0 ffee3000-fff04000 rwxp 00000000 00:00 0
Root cause: 宿主进程load 一个gcc4.7.2的共享库. 目前owner表示某些平台兼容这个lib做的不好, 导致一些异常的事情发生.
参考: https://bugs.chromium.org/p/chromium/issues/detail?id=29824
