Page MenuHomeFreeBSD

kqueue: Fix handling of marker knotes during fork
ClosedPublic

Authored by markj on Wed, Sep 9, 9:17 AM.
Tags
None
Referenced Files
F174209292: D59522.id188012.diff
Thu, Oct 1, 9:28 AM
F174209038: D59522.id186248.diff
Thu, Oct 1, 9:25 AM
F174208769: D59522.diff
Thu, Oct 1, 9:23 AM
Unknown Object (File)
Tue, Sep 29, 11:59 PM
Unknown Object (File)
Tue, Sep 29, 11:57 PM
Unknown Object (File)
Tue, Sep 29, 11:57 PM
Unknown Object (File)
Tue, Sep 29, 11:48 PM
Unknown Object (File)
Tue, Sep 29, 11:30 PM
Subscribers

Details

Summary

Commit d8bdcb08d0eb fixed a problem in kqueue_fork_copy_knote() where we
did not skip over marker knotes when copying. However, that fix was not
sufficient: we bump the influx counter and check for a marker after
dropping the kqueue lock. So, if multiple threads in a process are
forking concurrently, kqueue_fork_copy_list() may mark a marker as
in-flux and drop the lock; if the marker owner then frees the marker,
the first thread will decrement the in-flux counter of a freed knotes.
This use-after-free can be exploited, at least prior to commit
d8bdcb08d0eb, which (inadvertently) makes exploitation more challenging.

Reported by: Reo Shiseki

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

markj held this revision as a draft.
markj published this revision for review.Wed, Sep 9, 9:18 AM
markj edited the summary of this revision. (Show Details)
markj added reviewers: kib, secteam.
markj changed the visibility from "Public (No Login Required)" to "Subscribers".
markj changed the edit policy from "All Users" to "Subscribers".
markj edited subscribers, added: kib, secteam; removed: imp, olce.
This revision is now accepted and ready to land.Wed, Sep 9, 10:08 PM
markj changed the visibility from "Subscribers" to "Public (No Login Required)".Tue, Sep 29, 4:17 PM
markj changed the edit policy from "Subscribers" to "All Users".