Cache invalidation in Linux memory management
Summary
Jann Horn analyses CVE-2018-17182, in which stale VMA cache entries created an exploitable kernel state after memory changes. The bug was assigned CVE-2018-17182. Kernels from version 3.16 onwards were affected.
Ideas
- Page faults look up the responsible virtual memory region.
- A per-thread cache speeds up repeated VMA lookups.
- mremap did not fully invalidate the cache states involved.
- Stale pointers enabled a use-after-free attack in the kernel.
Insights
- Cache correctness is part of the security boundary and not just a performance detail.
- Optimisations multiply the states that every change has to keep consistent.
- Kernel configuration can greatly change the practical exploitability of the same bug.
Facts
- Several stable kernel series received fixes in September 2018.
Recommendations
- Install kernel security updates promptly and reboot afterwards.
- Specifically check optimisation paths for complete invalidation.
References
Links to the original source and the Web Archive open in a new tab.