summaryrefslogtreecommitdiffstats
path: root/lib
diff options
context:
space:
mode:
authorWilly Tarreau <w@1wt.eu>2020-07-10 15:23:19 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2020-08-21 11:01:52 +0200
commit5aa78397e208b6871a8bdec7fa2bd6992b1f3e4b (patch)
treea80d0f77199debfbc4435f7ffd9d7e136d5a8dda /lib
parentdfd6b6e82b18be81e19cb3a29872b2814ae939f4 (diff)
downloadlinux-stable-5aa78397e208b6871a8bdec7fa2bd6992b1f3e4b.tar.gz
linux-stable-5aa78397e208b6871a8bdec7fa2bd6992b1f3e4b.tar.bz2
linux-stable-5aa78397e208b6871a8bdec7fa2bd6992b1f3e4b.zip
random32: update the net random state on interrupt and activity
commit f227e3ec3b5cad859ad15666874405e8c1bbc1d4 upstream. This modifies the first 32 bits out of the 128 bits of a random CPU's net_rand_state on interrupt or CPU activity to complicate remote observations that could lead to guessing the network RNG's internal state. Note that depending on some network devices' interrupt rate moderation or binding, this re-seeding might happen on every packet or even almost never. In addition, with NOHZ some CPUs might not even get timer interrupts, leaving their local state rarely updated, while they are running networked processes making use of the random state. For this reason, we also perform this update in update_process_times() in order to at least update the state when there is user or system activity, since it's the only case we care about. Reported-by: Amit Klein <aksecurity@gmail.com> Suggested-by: Linus Torvalds <torvalds@linux-foundation.org> Cc: Eric Dumazet <edumazet@google.com> Cc: "Jason A. Donenfeld" <Jason@zx2c4.com> Cc: Andy Lutomirski <luto@kernel.org> Cc: Kees Cook <keescook@chromium.org> Cc: Thomas Gleixner <tglx@linutronix.de> Cc: Peter Zijlstra <peterz@infradead.org> Cc: <stable@vger.kernel.org> Signed-off-by: Willy Tarreau <w@1wt.eu> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'lib')
-rw-r--r--lib/random32.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/random32.c b/lib/random32.c
index fa594b1140e6..f1eb3dce03bd 100644
--- a/lib/random32.c
+++ b/lib/random32.c
@@ -47,7 +47,7 @@ static inline void prandom_state_selftest(void)
}
#endif
-static DEFINE_PER_CPU(struct rnd_state, net_rand_state) __latent_entropy;
+DEFINE_PER_CPU(struct rnd_state, net_rand_state) __latent_entropy;
/**
* prandom_u32_state - seeded pseudo-random number generator.