NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

kern/60805: LFS can write uninitialized kernel memory to disk



>Number:         60805
>Category:       kern
>Synopsis:       LFS can write uninitialized kernel memory to disk
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Sat Sep 26 16:30:01 +0000 2026
>Originator:     Shinichi Doyashiki
>Release:        11.99.8 around 2026-09-26 14:00 JST
>Organization:
at home
>Environment:
NetBSD kanade2.hq.csel.org 11.99.8 NetBSD 11.99.8 (KANADE2_12) #23: Sat Sep 26 17:31:38 JST 2026  clare%kanade2.hq.csel.org@localhost:/export/netbsd/debuglfs/src/sys/arch/amd64/compile/KANADE2_12 amd64
>Description:
LFS can write uninitialized kernel memory to disk
(when used with large block sizes, may be)

please see test script bellow (how to repeat)

>How-To-Repeat:
#!/bin/sh
# LFS can write uninitialized kernel memory to disk
#
# After this test, the raw filesystem image may contain strings from the
# running kernel. The leaked strings depend on the running system and are
# not deterministic.
#
# For a better chance of observing leaked strings, populate another mounted
# filesystem (for example an FFS source tree) before running this test.
#
# Prepare and use an empty 32MB block device (or partition) for LFS testing.
# The script overwrites the entire device (or partition) with zeros.
#
DISK=/dev/dk4
RDISK=/dev/rdk4

mkdir -p /testlfs

runtest () {
dd if=/dev/zero of=$RDISK bs=1m
newfs_lfs -f4k -b32k $RDISK
count=0
while [ $count -lt $maxcount ]; do
  count=`expr $count + 1`
  echo "===> MOUNT $count"
  if mount_lfs -n $DISK /testlfs; then
    echo "===> GOOD mount"
  else
    echo "===> BAD mount"
    exit 1
  fi
  echo "===> try file access"
  {
    cd /testlfs
    dd if=/dev/zero of=testfile.bin bs=1m count=1
    sync
    rm testfile.bin
    cd ..
  }
  echo "===> try umount"
  if umount /testlfs; then
    echo "===> GOOD umount"
  else
    echo "===> BAD umount"
    exit 1
  fi
  if fsck_lfs -nf $RDISK; then
    echo "===> GOOD fsck_lfs"
  else
    echo "===> BAD fsck_lfs"
    exit 1
  fi
done
}

maxcount=30
runtest
echo "===> try to dump filesystem"
hexdump -C $RDISK > /testlfs.hexdump.txt
strings $RDISK > /testlfs.strings.txt
echo "===> inspect /testlfs.hexdump.txt or /testlfs.strings.txt"
echo "===> look for strings that were never written by this test workload"

>Fix:
unknown




Home | Main Index | Thread Index | Old Index