Page MenuHomeFreeBSD

kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()
ClosedPublic

Authored by markj on Tue, Sep 22, 7:06 PM.
Tags
None
Referenced Files
F174269738: D59916.id187470.diff
Thu, Oct 1, 9:41 PM
F174211975: D59916.id188013.diff
Thu, Oct 1, 9:54 AM
F174211586: D59916.diff
Thu, Oct 1, 9:50 AM
F174170641: D59916.id187470.diff
Thu, Oct 1, 3:05 AM
Unknown Object (File)
Wed, Sep 30, 1:49 AM
Unknown Object (File)
Wed, Sep 30, 1:34 AM
Unknown Object (File)
Wed, Sep 30, 12:47 AM
Unknown Object (File)
Wed, Sep 30, 12:05 AM
Subscribers

Details

Summary

Here, fdp points to the new fdtable, copied from that of the parent
process. There is a window after the fdtable is copied, and before
kqueue_fork_copy_knote() runs, where a thread in the parent could have
grown the parent's fdtable and registered a knote with ident larger than
the size of the child's fdtable.

Add a bounds check for this case; skip the knote if it is referencing a
non-existent file.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

markj held this revision as a draft.
markj published this revision for review.Tue, Sep 22, 7:07 PM
markj added reviewers: kib, secteam.
markj changed the visibility from "Public (No Login Required)" to "Subscribers".
markj changed the edit policy from "All Users" to "Subscribers".
markj edited subscribers, added: kib, secteam; removed: imp, olce.
This revision is now accepted and ready to land.Tue, Sep 22, 8:06 PM
markj changed the visibility from "Subscribers" to "Public (No Login Required)".Tue, Sep 29, 4:17 PM
markj changed the edit policy from "Subscribers" to "All Users".