using latest patch - grsecurity-3.1-4.2.6-201511232037.patch
I got two size overflows and were not able to boot. After manually commenting out do_group_exit(SIGKILL) in fs/exec.c related to SIZE_OVERFLOW, I am at least able to boot and give out full details:
1st one:
- Code: Select all
[ 0.248790] PAX: size overflow detected in function zlib_decompress_setup crypto/zlib.c:226 cicus.89_58 max, count: 43, decl: decomp_windowBits; num: 0; context: zlib_ctx;
[ 0.249132] CPU: 0 PID: 72 Comm: cryptomgr_test Not tainted 4.2.6 #5
[ 0.249133] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
[ 0.249138] ffff88002df46e38 00000000fffffff5 ffff88002df46e38 00000000fffffff5
[ 0.249140] ffffffff81283f62 0000000000000000 ffffffff81618028 ffff88002df46e38
[ 0.249142] 8000000000000000 ffffffff8183b1c0 ffffffff81254573 0000000000000000
[ 0.249143] Call Trace:
[ 0.249155] [<ffffffff81283f62>] ? zlib_decompress_setup+0x122/0x130
[ 0.249162] [<ffffffff81254573>] ? test_pcomp+0x343/0x630
[ 0.249164] [<ffffffff81254b12>] ? alg_test_pcomp+0x52/0xa0
[ 0.249166] [<ffffffff81258b79>] ? alg_test+0xc9/0x290
[ 0.249171] [<ffffffff8152ae73>] ? __schedule+0x363/0x98d
[ 0.249172] [<ffffffff81254170>] ? cryptomgr_probe+0xf0/0xf0
[ 0.249174] [<ffffffff812541a9>] ? cryptomgr_test+0x39/0x40
[ 0.249182] [<ffffffff8106b09b>] ? kthread+0xcb/0xf0
[ 0.249183] [<ffffffff8106afd0>] ? __kthread_parkme+0x70/0x70
[ 0.249186] [<ffffffff8152e3ce>] ? ret_from_fork+0x3e/0x70
[ 0.249187] [<ffffffff8106afd0>] ? __kthread_parkme+0x70/0x70
2nd one:
- Code: Select all
[ 0.249214] PAX: size overflow detected in function zlib_decompress_setup crypto/zlib.c:226 cicus.89_58 max, count: 43, decl: decomp_windowBits; num: 0; context: zlib_ctx;
[ 0.249540] CPU: 0 PID: 72 Comm: cryptomgr_test Not tainted 4.2.6 #5
[ 0.249541] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
[ 0.249542] ffff88002df46e38 00000000fffffff5 ffff88002df46e38 00000000fffffff5
[ 0.249543] ffffffff81283f62 0000000000000000 ffffffff81618028 ffff88002df46e38
[ 0.249545] 8000000000000000 ffffffff8183b5d8 ffffffff81254573 0000000000000000
[ 0.249546] Call Trace:
[ 0.249549] [<ffffffff81283f62>] ? zlib_decompress_setup+0x122/0x130
[ 0.249553] [<ffffffff81254573>] ? test_pcomp+0x343/0x630
[ 0.249556] [<ffffffff81254b12>] ? alg_test_pcomp+0x52/0xa0
[ 0.249557] [<ffffffff81258b79>] ? alg_test+0xc9/0x290
[ 0.249559] [<ffffffff8152ae73>] ? __schedule+0x363/0x98d
[ 0.249562] [<ffffffff81254170>] ? cryptomgr_probe+0xf0/0xf0
[ 0.249564] [<ffffffff812541a9>] ? cryptomgr_test+0x39/0x40
[ 0.249566] [<ffffffff8106b09b>] ? kthread+0xcb/0xf0
[ 0.249568] [<ffffffff8106afd0>] ? __kthread_parkme+0x70/0x70
[ 0.249571] [<ffffffff8152e3ce>] ? ret_from_fork+0x3e/0x70
[ 0.249573] [<ffffffff8106afd0>] ? __kthread_parkme+0x70/0x70
Debian Wheezy version:
- Code: Select all
root@xxx:~/bin/kernel_autocompile/linux-4.2.6# cat /etc/debian_version
7.9
GCC version:
- Code: Select all
root@xxx:~/bin/kernel_autocompile/linux-4.2.6# gcc -v
Using built-in specs.
COLLECT_GCC=gcc
COLLECT_LTO_WRAPPER=/usr/lib/gcc/x86_64-linux-gnu/4.7/lto-wrapper
Target: x86_64-linux-gnu
Configured with: ../src/configure -v --with-pkgversion='Debian 4.7.2-5' --with-bugurl=file:///usr/share/doc/gcc-4.7/README.Bugs --enable-languages=c,c++,go,fortran,objc,obj-c++ --prefix=/usr --program-suffix=-4.7 --enable-shared --enable-linker-build-id --with-system-zlib --libexecdir=/usr/lib --without-included-gettext --enable-threads=posix --with-gxx-include-dir=/usr/include/c++/4.7 --libdir=/usr/lib --enable-nls --with-sysroot=/ --enable-clocale=gnu --enable-libstdcxx-debug --enable-libstdcxx-time=yes --enable-gnu-unique-object --enable-plugin --enable-objc-gc --with-arch-32=i586 --with-tune=generic --enable-checking=release --build=x86_64-linux-gnu --host=x86_64-linux-gnu --target=x86_64-linux-gnu
Thread model: posix
gcc version 4.7.2 (Debian 4.7.2-5)
It's running as a VM under KVM on Vultr Cloud. I can also attach my .config, if needed.
There were also some compilation messages about some functions not being present in hash table, I will post these later when I try to recompile again.
If you need anything else, just let me know. Thanks in advance for resolving this!
With best regards,
AudioCricket