PAX: size overflow detected in function __vhost_add_used_n
Posted: Fri Oct 23, 2015 6:52 am
Using Gentoo's hardened-sources: Linux version 4.2.3-hardened-r5 (gcc version 4.9.3 (Gentoo Hardened 4.9.3 p1.0, pie-0.6.2) ) #1 SMP PREEMPT
Same .config as in https://forums.grsecurity.net/viewtopic.php?f=3&t=4283, but for some reason the EXTRA_CFLAGS trick doesn't generate any extra files any more.
- Code: Select all
[ 1891.545512] PAX: size overflow detected in function __vhost_add_used_n drivers/vhost/vhost.c:1517 cicus.394_113 max, count: 3, decl: last_used_idx; num: 0; context: vhost_virtqueue;
[ 1891.545517] CPU: 5 PID: 3728 Comm: vhost-3726 Not tainted 4.2.3-hardened-r5 #1
[ 1891.545518] Hardware name: LENOVO 20AN006VMS/20AN006VMS, BIOS GLET78WW (2.32 ) 03/03/2015
[ 1891.545520] ffffffffa2fcfc6b 1635b2bb646ff805 0000000000000000 ffffffffa2f42695
[ 1891.545522] ffffc9000401bb98 ffffffffa2a83730 0000000000000000 ffffffffa2f426ab
[ 1891.545524] ffffc9000401bbc8 ffffffffa21a10c3 ffff8803a8d50078 0000000000000001
[ 1891.545525] Call Trace:
[ 1891.545532] [<ffffffffa2a83730>] dump_stack+0x4c/0x79
[ 1891.545535] [<ffffffffa21a10c3>] report_size_overflow+0x33/0x60
[ 1891.545539] [<ffffffffa28487ba>] __vhost_add_used_n+0x15a/0x160
[ 1891.545540] [<ffffffffa284b0ad>] vhost_add_used_n+0x8d/0x190
[ 1891.545542] [<ffffffffa284b385>] vhost_add_used_and_signal_n+0x25/0x40
[ 1891.545544] [<ffffffffa2843a7e>] handle_rx+0x61e/0x920
[ 1891.545546] [<ffffffffa284b1fb>] ? vhost_add_used+0x4b/0x70
[ 1891.545547] [<ffffffffa2843d98>] handle_rx_net+0x18/0x20
[ 1891.545549] [<ffffffffa2847edd>] vhost_worker+0xdd/0x180
[ 1891.545551] [<ffffffffa2847e00>] ? vhost_poll_func+0x30/0x30
[ 1891.545555] [<ffffffffa20dc847>] kthread+0xd7/0xf0
[ 1891.545556] [<ffffffffa20dc770>] ? __kthread_parkme+0x80/0x80
[ 1891.545559] [<ffffffffa2a8cc4e>] ret_from_fork+0x3e/0x70
[ 1891.545561] [<ffffffffa20dc770>] ? __kthread_parkme+0x80/0x80
Same .config as in https://forums.grsecurity.net/viewtopic.php?f=3&t=4283, but for some reason the EXTRA_CFLAGS trick doesn't generate any extra files any more.