diff options
| author | Chris Mason <mason@kernel.org> | 2026-10-01 13:50:22 +0000 |
|---|---|---|
| committer | Peter Zijlstra <peterz@infradead.org> | 2026-10-02 11:47:13 +0200 |
| commit | f35e3b5784221654f9cdbd6222275a7fa203f6c3 (patch) | |
| tree | 350ec1fdd8ac210722291f1241c187bdef4eef44 /scripts/bootgraph.pl | |
| parent | 26f6b6357b1b06e6aaa9b8d796989cca785d8e1d (diff) | |
| download | linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.tar.gz linux-stable-f35e3b5784221654f9cdbd6222275a7fa203f6c3.zip | |
futex: Fix private hash use-after-free on resize
poll_state_synchronize_rcu(mm->futex.phash.batches) is used by
futex_ref_drop() to check that a grace period has passed since the
current hash was published. This relies on batches referencing a grace
period which started after the hash pointer was assigned.
__futex_pivot_hash() sets mmph->batches before it replaces mmph->hash:
scoped_guard(rcu) {
mmph->batches = get_state_synchronize_rcu();
rcu_assign_pointer(mmph->hash, new);
}
The scoped_guard(rcu) doesn't stop new grace periods from starting, and
if one starts between those two assignments, futex_ref_drop() can move
forward while a reader still holds a pointer to the old hash.
Fix things by setting mmph->batches after assigning mmph->hash. The
scoped_guard(rcu) isn't needed, so let's drop that as well.
Fixes: 56180dd20c19 ("futex: Use RCU-based per-CPU reference counting instead of rcuref_t")
Assisted-by: kres
Signed-off-by: Chris Mason <mason@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Paul E. McKenney <paulmck@kernel.org>
Link: https://patch.msgid.link/20261001135022.2220288-1-mason@kernel.org
Diffstat (limited to 'scripts/bootgraph.pl')
0 files changed, 0 insertions, 0 deletions
