openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
authorAli Ahmet Memis <ali@iusegentoo.com>
Fri, 21 Aug 2026 01:45:27 +0000 (01:45 +0000)
committerStafford Horne <shorne@gmail.com>
Sat, 29 Aug 2026 06:32:26 +0000 (07:32 +0100)
commit78004e9a87f240df03e2f73120d291763c32e0a7
tree137c22dd795222931b9d2bf2501d37cd766741aa
parent6620f5e8c11c4f7e41222a86f5c97150cc5f84a5
openrisc: fix arbitrary kernel memory access via or1k_atomic syscall

sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user
pointers, v1 and v2, and swaps the words they point to in hand-written
assembly.

    l.lwz   r29,0(r4)
    l.lwz   r27,0(r5)
    l.sw    0(r4),r27
    l.sw    0(r5),r29

The pointers are not checked with access_ok(). The four memory
accesses also have no exception table entries.

A caller passes a kernel address as either pointer, and the syscall
reads from and writes to it directly.

This gives an unprivileged process a kernel read/write primitive. It
overwrites kernel data such as the sys_call_table, gaining code
execution in kernel context.

Check both pointers before entering the critical section. Add fixups
for the four memory accesses so faults on valid but unmapped user
addresses return -EFAULT.

[shorne@gmail.com: fix comment style]
Fixes: 9d02a4283e9c ("OpenRISC: Boot code")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Signed-off-by: Stafford Horne <shorne@gmail.com>
arch/openrisc/kernel/entry.S