Page MenuHomeFreeBSD

unix: Fix handling of listening sockets during garbage collection
ClosedPublic

Authored by markj on Nov 13 2025, 7:42 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Dec 29, 12:36 AM
Unknown Object (File)
Sun, Dec 28, 6:04 AM
Unknown Object (File)
Fri, Dec 26, 10:51 AM
Unknown Object (File)
Mon, Dec 22, 2:43 AM
Unknown Object (File)
Thu, Dec 18, 12:34 PM
Unknown Object (File)
Dec 14 2025, 6:58 PM
Unknown Object (File)
Dec 1 2025, 10:25 AM
Unknown Object (File)
Nov 30 2025, 9:52 AM
Subscribers

Details

Summary

socantrcvmore() and unp_dispose() assume that the socket's socket
buffers are initialized, which isn't the case for listening sockets.

Reported by: syzbot+a62883292a5c257703be@syzkaller.appspotmail.com

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable