From: Tan Xiaojun Date: Thu, 23 Feb 2017 06:04:39 +0000 (+0800) Subject: perf/core: Fix the perf_cpu_time_max_percent check X-Git-Tag: v4.1.12-124.31.3~352 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=caac7d1e19c76c62b0a866fdfea9c022c2adb84b;p=users%2Fjedix%2Flinux-maple.git perf/core: Fix the perf_cpu_time_max_percent check Use "proc_dointvec_minmax" instead of "proc_dointvec" to check the input value from user-space. If not, we can set a big value and some vars will overflow like "sysctl_perf_event_sample_rate" which will cause a lot of unexpected problems. Signed-off-by: Tan Xiaojun Signed-off-by: Peter Zijlstra (Intel) Cc: Cc: Cc: Alexander Shishkin Cc: Arnaldo Carvalho de Melo Cc: Jiri Olsa Cc: Linus Torvalds Cc: Peter Zijlstra Cc: Stephane Eranian Cc: Thomas Gleixner Cc: Vince Weaver Link: http://lkml.kernel.org/r/1487829879-56237-1-git-send-email-tanxiaojun@huawei.com Signed-off-by: Ingo Molnar (cherry picked from commit 1572e45a924f254d9570093abde46430c3172e3d) Orabug: 27823815 CVE: CVE-2017-18255 Reviewed-by: Darren Kenny Signed-off-by: Allen Pais Signed-off-by: Brian Maly --- diff --git a/kernel/events/core.c b/kernel/events/core.c index 651ce2fe366e..92fc693cf1b4 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -226,7 +226,7 @@ int perf_cpu_time_max_percent_handler(struct ctl_table *table, int write, void __user *buffer, size_t *lenp, loff_t *ppos) { - int ret = proc_dointvec(table, write, buffer, lenp, ppos); + int ret = proc_dointvec_minmax(table, write, buffer, lenp, ppos); if (ret || !write) return ret;