mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
synced 2026-09-26 18:16:26 +00:00
net: bpf: arm: address randomize and write protect JIT code
This is the ARM variant for314beb9bca("x86: bpf_jit_comp: secure bpf jit against spraying attacks"). It is now possible to implement it due to commits75374ad47c("ARM: mm: Define set_memory_* functions for ARM") anddca9aa92fc("ARM: add DEBUG_SET_MODULE_RONX option to Kconfig") which added infrastructure for this facility. Thus, this patch makes sure the BPF generated JIT code is marked RO, as other kernel text sections, and also lets the generated JIT code start at a pseudo random offset instead on a page boundary. The holes are filled with illegal instructions. JIT tested on armv7hl with BPF test suite. Reference: http://mainisusuallyafunction.blogspot.com/2012/11/attacking-hardened-linux-systems-with.html Signed-off-by: Daniel Borkmann <dborkman@redhat.com> Signed-off-by: Alexei Starovoitov <ast@plumgrid.com> Acked-by: Mircea Gherzan <mgherzan@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
738cbe72ad
commit
55309dd3d4
1 changed files with 26 additions and 6 deletions
Loading…
Add table
Add a link
Reference in a new issue