summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorChris Mason <mason@kernel.org>2026-10-01 13:50:22 +0000
committerPeter Zijlstra <peterz@infradead.org>2026-10-02 11:47:13 +0200
commitf35e3b5784221654f9cdbd6222275a7fa203f6c3 (patch)
tree350ec1fdd8ac210722291f1241c187bdef4eef44
parent26f6b6357b1b06e6aaa9b8d796989cca785d8e1d (diff)
downloadlinux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.tar.gz
linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.zip
futex: Fix private hash use-after-free on resize
poll_state_synchronize_rcu(mm->futex.phash.batches) is used by futex_ref_drop() to check that a grace period has passed since the current hash was published. This relies on batches referencing a grace period which started after the hash pointer was assigned. __futex_pivot_hash() sets mmph->batches before it replaces mmph->hash: scoped_guard(rcu) { mmph->batches = get_state_synchronize_rcu(); rcu_assign_pointer(mmph->hash, new); } The scoped_guard(rcu) doesn't stop new grace periods from starting, and if one starts between those two assignments, futex_ref_drop() can move forward while a reader still holds a pointer to the old hash. Fix things by setting mmph->batches after assigning mmph->hash. The scoped_guard(rcu) isn't needed, so let's drop that as well. Fixes: 56180dd20c19 ("futex: Use RCU-based per-CPU reference counting instead of rcuref_t") Assisted-by: kres Signed-off-by: Chris Mason <mason@kernel.org> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Reviewed-by: Paul E. McKenney <paulmck@kernel.org> Link: https://patch.msgid.link/20261001135022.2220288-1-mason@kernel.org
-rw-r--r--kernel/futex/core.c10
1 files changed, 6 insertions, 4 deletions
diff --git a/kernel/futex/core.c b/kernel/futex/core.c
index a061f54b6..095f9fe44 100644
--- a/kernel/futex/core.c
+++ b/kernel/futex/core.c
@@ -213,10 +213,12 @@ static bool __futex_pivot_hash(struct mm_struct *mm, struct futex_private_hash *
futex_rehash_private(fph, new);
}
new->state = FR_PERCPU;
- scoped_guard(rcu) {
- mmph->batches = get_state_synchronize_rcu();
- rcu_assign_pointer(mmph->hash, new);
- }
+ rcu_assign_pointer(mmph->hash, new);
+ /*
+ * mmph->batches must reference a grace period which started after
+ * mmph->hash was assigned. See futex_ref_drop().
+ */
+ mmph->batches = get_state_synchronize_rcu();
kvfree_rcu(fph, rcu);
return true;
}