summaryrefslogtreecommitdiffstats
path: root/scripts/Kbuild.include
diff options
context:
space:
mode:
authorChris Mason <mason@kernel.org>2026-10-01 13:50:22 +0000
committerPeter Zijlstra <peterz@infradead.org>2026-10-02 11:47:13 +0200
commitf35e3b5784221654f9cdbd6222275a7fa203f6c3 (patch)
tree350ec1fdd8ac210722291f1241c187bdef4eef44 /scripts/Kbuild.include
parent26f6b6357b1b06e6aaa9b8d796989cca785d8e1d (diff)
downloadlinux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.tar.gz
linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.zip
futex: Fix private hash use-after-free on resize
poll_state_synchronize_rcu(mm->futex.phash.batches) is used by futex_ref_drop() to check that a grace period has passed since the current hash was published. This relies on batches referencing a grace period which started after the hash pointer was assigned. __futex_pivot_hash() sets mmph->batches before it replaces mmph->hash: scoped_guard(rcu) { mmph->batches = get_state_synchronize_rcu(); rcu_assign_pointer(mmph->hash, new); } The scoped_guard(rcu) doesn't stop new grace periods from starting, and if one starts between those two assignments, futex_ref_drop() can move forward while a reader still holds a pointer to the old hash. Fix things by setting mmph->batches after assigning mmph->hash. The scoped_guard(rcu) isn't needed, so let's drop that as well. Fixes: 56180dd20c19 ("futex: Use RCU-based per-CPU reference counting instead of rcuref_t") Assisted-by: kres Signed-off-by: Chris Mason <mason@kernel.org> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Reviewed-by: Paul E. McKenney <paulmck@kernel.org> Link: https://patch.msgid.link/20261001135022.2220288-1-mason@kernel.org
Diffstat (limited to 'scripts/Kbuild.include')
0 files changed, 0 insertions, 0 deletions