On Mon, Oct 15, 2018 at 06:54:31AM -0700, Omer Tripp wrote:
Hi Greg and all,
Here is my analysis of the complete gadget, and looking forward to your corrections/feedback if there are any inaccuracies:
__close_fd() is reachable via the close() syscall with a user-controlled fd. 2.
If said bounds check is mispredicted, then a user-controlled address fdt->fd[fd] is obtained then dereferenced, and the value of a user-controlled address is loaded into the local variable file. 3.
file is then passed as an argument to filp_close, where the cache lines secret
- offsetof(f_op) and secret + offsetof(f_mode) are hot and vulnerable to
a timing channel attack.
The mitigation proposed by Greg Hackmann blocks this gadget.
What ever happened to this patch? Did it get reposted? If not, can someone please do so with this text in the changelog?
thanks,
greg k-h
linux-stable-mirror@lists.linaro.org