diff options
author | Al Viro <viro@zeniv.linux.org.uk> | 2021-09-24 00:35:42 +0000 |
---|---|---|
committer | Guo Ren <guoren@linux.alibaba.com> | 2021-10-16 07:20:12 +0800 |
commit | fbd63c08cdcca5fb1315aca3172b3c9c272cfb4f (patch) | |
tree | 9f452d718901cf5786f42de5f8401ba295a65970 /tools/perf/scripts/python/exported-sql-viewer.py | |
parent | 64570fbc14f8d7cb3fe3995f20e26bc25ce4b2cc (diff) |
csky: don't let sigreturn play with priveleged bits of status register
csky restore_sigcontext() blindly overwrites regs->sr with the value
it finds in sigcontext. Attacker can store whatever they want in there,
which includes things like S-bit. Userland shouldn't be able to set
that, or anything other than C flag (bit 0).
Do the same thing other architectures with protected bits in flags
register do - preserve everything that shouldn't be settable in
user mode, picking the rest from the value saved is sigcontext.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Guo Ren <guoren@kernel.org>
Cc: stable@vger.kernel.org
Diffstat (limited to 'tools/perf/scripts/python/exported-sql-viewer.py')
0 files changed, 0 insertions, 0 deletions