NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
kern/60803: LFS can write uninitialized kernel memory to disk
>Number: 60803
>Category: kern
>Synopsis: LFS can write uninitialized kernel memory to disk
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: kern-bug-people
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Sat Sep 26 16:20:01 +0000 2026
>Originator: Shinichi Doyashiki
>Release: 11.99.8 around 2026-09-26 14:00 JST
>Organization:
at home
>Environment:
NetBSD kanade2.hq.csel.org 11.99.8 NetBSD 11.99.8 (KANADE2_12) #23: Sat Sep 26 17:31:38 JST 2026 clare%kanade2.hq.csel.org@localhost:/export/netbsd/debuglfs/src/sys/arch/amd64/compile/KANADE2_12 amd64
>Description:
LFS can write uninitialized kernel memory to disk
(when used with large block sizes, may be)
please see test script bellow (how to repeat)
>How-To-Repeat:
#!/bin/sh
# LFS can write uninitialized kernel memory to disk
#
# After this test, the raw filesystem image may contain strings from the
# running kernel. The leaked strings depend on the running system and are
# not deterministic.
#
# For a better chance of observing leaked strings, populate another mounted
# filesystem (for example an FFS source tree) before running this test.
#
# Prepare and use an empty 32MB block device (or partition) for LFS testing.
# The script overwrites the entire device (or partition) with zeros.
#
DISK=/dev/dk4
RDISK=/dev/rdk4
mkdir -p /testlfs
runtest () {
dd if=/dev/zero of=$RDISK bs=1m
newfs_lfs -f4k -b32k $RDISK
count=0
while [ $count -lt $maxcount ]; do
count=`expr $count + 1`
echo "===> MOUNT $count"
if mount_lfs -n $DISK /testlfs; then
echo "===> GOOD mount"
else
echo "===> BAD mount"
exit 1
fi
echo "===> try file access"
{
cd /testlfs
dd if=/dev/zero of=testfile.bin bs=1m count=1
sync
rm testfile.bin
cd ..
}
echo "===> try umount"
if umount /testlfs; then
echo "===> GOOD umount"
else
echo "===> BAD umount"
exit 1
fi
if fsck_lfs -nf $RDISK; then
echo "===> GOOD fsck_lfs"
else
echo "===> BAD fsck_lfs"
exit 1
fi
done
}
maxcount=30
runtest
echo "===> try to dump filesystem"
hexdump -C $RDISK > /testlfs.hexdump.txt
strings $RDISK > /testlfs.strings.txt
echo "===> inspect /testlfs.hexdump.txt or /testlfs.strings.txt"
echo "===> look for strings that were never written by this test workload"
>Fix:
unknown
Home |
Main Index |
Thread Index |
Old Index