Page MenuHomeFreeBSD

sysv_sem: fix the loop that compacts sem array on semaphores removal.
ClosedPublic

Authored by kib on Feb 15 2020, 11:11 AM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Dec 4, 10:20 AM
Unknown Object (File)
Thu, Nov 27, 10:09 PM
Unknown Object (File)
Mon, Nov 10, 11:12 PM
Unknown Object (File)
Oct 31 2025, 3:11 AM
Unknown Object (File)
Oct 15 2025, 2:24 AM
Unknown Object (File)
Oct 15 2025, 1:54 AM
Unknown Object (File)
Oct 15 2025, 1:21 AM
Unknown Object (File)
Oct 14 2025, 1:58 AM
Subscribers

Details

Summary

As written now, it copies random kernel memory from beyond the bounds of the array.

While there, use designated initialisers for seminfo, and add assert in sem_remove() that sema is sane. [These will be separate commits].

Reported and tested by: pho

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable