diff options
| author | Chris Mason <mason@kernel.org> | 2026-10-01 13:50:22 +0000 |
|---|---|---|
| committer | Peter Zijlstra <peterz@infradead.org> | 2026-10-02 11:47:13 +0200 |
| commit | f35e3b5784221654f9cdbd6222275a7fa203f6c3 (patch) | |
| tree | 350ec1fdd8ac210722291f1241c187bdef4eef44 | |
| parent | 26f6b6357b1b06e6aaa9b8d796989cca785d8e1d (diff) | |
| download | linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.tar.gz linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.zip | |
futex: Fix private hash use-after-free on resize
poll_state_synchronize_rcu(mm->futex.phash.batches) is used by
futex_ref_drop() to check that a grace period has passed since the
current hash was published. This relies on batches referencing a grace
period which started after the hash pointer was assigned.
__futex_pivot_hash() sets mmph->batches before it replaces mmph->hash:
scoped_guard(rcu) {
mmph->batches = get_state_synchronize_rcu();
rcu_assign_pointer(mmph->hash, new);
}
The scoped_guard(rcu) doesn't stop new grace periods from starting, and
if one starts between those two assignments, futex_ref_drop() can move
forward while a reader still holds a pointer to the old hash.
Fix things by setting mmph->batches after assigning mmph->hash. The
scoped_guard(rcu) isn't needed, so let's drop that as well.
Fixes: 56180dd20c19 ("futex: Use RCU-based per-CPU reference counting instead of rcuref_t")
Assisted-by: kres
Signed-off-by: Chris Mason <mason@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Paul E. McKenney <paulmck@kernel.org>
Link: https://patch.msgid.link/20261001135022.2220288-1-mason@kernel.org
| -rw-r--r-- | kernel/futex/core.c | 10 |
1 files changed, 6 insertions, 4 deletions
diff --git a/kernel/futex/core.c b/kernel/futex/core.c index a061f54b6..095f9fe44 100644 --- a/kernel/futex/core.c +++ b/kernel/futex/core.c @@ -213,10 +213,12 @@ static bool __futex_pivot_hash(struct mm_struct *mm, struct futex_private_hash * futex_rehash_private(fph, new); } new->state = FR_PERCPU; - scoped_guard(rcu) { - mmph->batches = get_state_synchronize_rcu(); - rcu_assign_pointer(mmph->hash, new); - } + rcu_assign_pointer(mmph->hash, new); + /* + * mmph->batches must reference a grace period which started after + * mmph->hash was assigned. See futex_ref_drop(). + */ + mmph->batches = get_state_synchronize_rcu(); kvfree_rcu(fph, rcu); return true; } |
