Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2
Date: Fri, 27 Jan 2012 16:07:41
Message-Id: c08bab38cf6d295c88df012138257c5e.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2 by "Tóth Attila"
1 And this one is from my laptop:
2 vmalloc: allocation failure: 0 bytes
3 modprobe: page allocation failure: order:0, mode:0x80d2
4 Pid: 3157, comm: modprobe Tainted: G O 3.2.1-hardened #1
5 Call Trace:
6 [<000080d2>] ? old_ich_force_enable_hpet+0x52/0x140
7 [<0008922b>] ? warn_alloc_failed+0xbb/0x100
8 [<000080d2>] ? old_ich_force_enable_hpet+0x52/0x140
9 [<000a8a11>] ? __vmalloc_node_range+0x1c1/0x260
10 [<000080d2>] ? old_ich_force_enable_hpet+0x52/0x140
11 [<0001ac3e>] ? module_alloc+0x7e/0x90
12 [<000080d2>] ? old_ich_force_enable_hpet+0x52/0x140
13 [<00060053>] ? module_alloc_update_bounds_rw+0x13/0x60
14 [<00060053>] ? module_alloc_update_bounds_rw+0x13/0x60
15 [<00060ac1>] ? sys_init_module+0xa01/0x1af0
16 [<000051f4>] ? smp_x86_platform_ipi+0x44/0x60
17 [<0000297c>] ? prepare_to_copy+0xc/0xb0
18 [<0000299c>] ? prepare_to_copy+0x2c/0xb0
19 [<0061396c>] ? syscall_call+0x7/0xb
20 [<000051f4>] ? smp_x86_platform_ipi+0x44/0x60
21 [<0001f7e0>] ? vmalloc_sync_all+0xf0/0xf0
22 [<0061398c>] ? restore_all_pax+0xc/0xc
23 [<0061007b>] ? snd_intel8x0m_probe+0x36e/0x635
24 [<00010202>] ? x86_schedule_events+0x122/0x2c0
25 [<00010202>] ? x86_schedule_events+0x122/0x2c0
26 Mem-Info:
27 DMA per-cpu:
28 CPU 0: hi: 0, btch: 1 usd: 0
29 Normal per-cpu:
30 CPU 0: hi: 186, btch: 31 usd: 126
31 HighMem per-cpu:
32 CPU 0: hi: 186, btch: 31 usd: 31
33 active_anon:523 inactive_anon:72 isolated_anon:0
34 active_file:2369 inactive_file:2790 isolated_file:0
35 unevictable:0 dirty:11 writeback:0 unstable:0
36 free:502375 slab_reclaimable:625 slab_unreclaimable:1183
37 mapped:570 shmem:89 pagetables:59 bounce:0
38 DMA free:15928kB min:64kB low:80kB high:96kB active_anon:0kB
39 inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB
40 isolated(anon):0kB isolated(file):0kB present:15804kB mlocked:0kB
41 dirty:0kB writeback:0kB mapped:0kB shmem:0kB slab_reclaimable:0kB
42 slab_unreclaimable:0kB kernel_stack:0kB pagetables:0kB unstable:0kB
43 bounce:0kB writeback_tmp:0kB pages_scanned:0 all_unreclaimable? no
44 lowmem_reserve[]: 0 865 2015 2015
45 Normal free:826824kB min:3728kB low:4660kB high:5592kB active_anon:0kB
46 inactive_anon:0kB active_file:1716kB inactive_file:1444kB unevictable:0kB
47 isolated(anon):0kB isolated(file):0kB present:885944kB mlocked:0kB
48 dirty:44kB writeback:0kB mapped:4kB shmem:0kB slab_reclaimable:2500kB
49 slab_unreclaimable:4732kB kernel_stack:488kB pagetables:236kB unstable:0kB
50 bounce:0kB writeback_tmp:0kB pages_scanned:0 all_unreclaimable? no
51 lowmem_reserve[]: 0 0 9202 9202
52 HighMem free:1166748kB min:512kB low:1748kB high:2988kB active_anon:2092kB
53 inactive_anon:288kB active_file:7760kB inactive_file:9716kB
54 unevictable:0kB isolated(anon):0kB isolated(file):0kB present:1177932kB
55 mlocked:0kB dirty:0kB writeback:0kB mapped:2276kB shmem:356kB
56 slab_reclaimable:0kB slab_unreclaimable:0kB kernel_stack:0kB
57 pagetables:0kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:0
58 all_unreclaimable? no
59 lowmem_reserve[]: 0 0 0 0
60 DMA: 0*4kB 1*8kB 1*16kB 1*32kB 2*64kB 1*128kB 1*256kB 0*512kB 1*1024kB
61 1*2048kB 3*4096kB = 15928kB
62 Normal: 116*4kB 67*8kB 46*16kB 10*32kB 5*64kB 3*128kB 3*256kB 0*512kB
63 2*1024kB 3*2048kB 199*4096kB = 826824kB
64 HighMem: 1*4kB 69*8kB 85*16kB 33*32kB 16*64kB 2*128kB 3*256kB 3*512kB
65 1*1024kB 2*2048kB 282*4096kB = 1166748kB
66 5258 total pagecache pages
67 0 pages in swap cache
68 Swap cache stats: add 0, delete 0, find 0/0
69 Free swap = 0kB
70 Total swap = 0kB
71 524112 pages RAM
72 296802 pages HighMem
73 12058 pages reserved
74 3473 pages shared
75 7713 pages non-shared
76
77 But modules are still get loaded somehow and working.
78 --
79 dr Tóth Attila, Radiológus, 06-20-825-8057
80 Attila Toth MD, Radiologist, +36-20-825-8057
81
82 2012.Január 27.(P) 17:02 időpontban "Tóth Attila" ezt írta:
83 > I've just had this one while booting hardened-3.2.1:
84 > Jan 27 16:40:29 atoth kernel: vmalloc: allocation failure: 0 bytes
85 > Jan 27 16:40:29 atoth kernel: modprobe: page allocation failure: order:0,
86 > mode:0x80d2
87 > Jan 27 16:40:29 atoth kernel: Pid: 7460, comm: modprobe Not tainted
88 > 3.2.1-hardened #1
89 > Jan 27 16:40:29 atoth kernel: Call Trace:
90 > Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
91 > Jan 27 16:40:29 atoth kernel: [<000a0e1f>] ? warn_alloc_failed+0xbf/0x100
92 > Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
93 > Jan 27 16:40:29 atoth kernel: [<000c3cc3>] ?
94 > __vmalloc_node_range+0x1a3/0x240
95 > Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
96 > Jan 27 16:40:29 atoth kernel: [<00637cb5>] ?
97 > __mutex_lock_slowpath+0x1a5/0x240
98 > Jan 27 16:40:29 atoth kernel: [<00020b8e>] ? module_alloc+0x7e/0x90
99 > Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
100 > Jan 27 16:40:29 atoth kernel: [<000728a3>] ?
101 > module_alloc_update_bounds_rw+0x13/0x60
102 > Jan 27 16:40:29 atoth kernel: [<000728a3>] ?
103 > module_alloc_update_bounds_rw+0x13/0x60
104 > Jan 27 16:40:29 atoth kernel: [<00073196>] ? load_module+0x886/0x1b70
105 > Jan 27 16:40:29 atoth kernel: [<00002c59>] ? __switch_to+0xb9/0x210
106 > Jan 27 16:40:29 atoth kernel: [<000744ca>] ? sys_init_module+0x4a/0x1d0
107 > Jan 27 16:40:29 atoth kernel: [<00010246>] ? switch_to_new_gdt+0x26/0x30
108 > Jan 27 16:40:29 atoth kernel: [<00638d71>] ? syscall_call+0x7/0xb
109 > Jan 27 16:40:29 atoth kernel: [<00002c59>] ? __switch_to+0xb9/0x210
110 > Jan 27 16:40:29 atoth kernel: [<00010246>] ? switch_to_new_gdt+0x26/0x30
111 >
112 > It's there for every module loading. Even though modules seems to work.
113 > Strange. The kernel also didn't logged the first page of dmesg in
114 > kernel.log.
115 >
116 > I don't experience this using hardened-3.1.8.
117 > I don't know if it's a known problem. I'll try hardened-3.2.2 later.
118 >
119 > Thanks:
120 > Dw.
121 > --
122 > dr Tóth Attila, Radiológus, 06-20-825-8057
123 > Attila Toth MD, Radiologist, +36-20-825-8057
124 >
125 > 2012.Január 27.(P) 14:37 időpontban Anthony G. Basile ezt írta:
126 >> Hi everyone,
127 >>
128 >> I just added hardened-sources 2.6.32-r88 and 3.2.2 to the tree. They
129 >> address CVE-2012-0056. I've tested and they do indeed resist the
130 >> exploit. I will be stabilizing them within 24 hours. However, I feel
131 >> very uncomfortable doing so because I don't want to trade one set of
132 >> problems with another. If anyone has time to test, let me know if you
133 >> encounter any issues.
134 >>
135 >> --
136 >> Anthony G. Basile, Ph. D.
137 >> Chair of Information Technology
138 >> D'Youville College
139 >> Buffalo, NY 14201
140 >> (716) 829-8197
141 >>
142 >
143 >
144 >
145 >

Replies