bk99.de entertain the web since 1997

Cache invalidation in Linux memory management

Summary

Jann Horn analyses CVE-2018-17182, in which stale VMA cache entries created an exploitable kernel state after memory changes. The bug was assigned CVE-2018-17182. Kernels from version 3.16 onwards were affected.

Ideas

  • Page faults look up the responsible virtual memory region.
  • A per-thread cache speeds up repeated VMA lookups.
  • mremap did not fully invalidate the cache states involved.
  • Stale pointers enabled a use-after-free attack in the kernel.

Insights

  • Cache correctness is part of the security boundary and not just a performance detail.
  • Optimisations multiply the states that every change has to keep consistent.
  • Kernel configuration can greatly change the practical exploitability of the same bug.

Facts

  • Several stable kernel series received fixes in September 2018.

Recommendations

  • Install kernel security updates promptly and reboot afterwards.
  • Specifically check optimisation paths for complete invalidation.

References

Read the original article

Search the Web Archive