Commit 8eeee4e2 authored by Oleg Nesterov's avatar Oleg Nesterov Committed by Linus Torvalds

send_sigio_to_task: sanitize the usage of fown->signum

send_sigio_to_task() reads fown->signum several times, we can race with
F_SETSIG which changes ->signum lockless.  In theory, this can fool
security checks or we can call group_send_sig_info() with the wrong
->si_signo which does not match "int sig".

Change the code to cache ->signum.
Signed-off-by: default avatarOleg Nesterov <oleg@redhat.com>
Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
parent f83b1e61
...@@ -432,10 +432,16 @@ static void send_sigio_to_task(struct task_struct *p, ...@@ -432,10 +432,16 @@ static void send_sigio_to_task(struct task_struct *p,
int fd, int fd,
int reason) int reason)
{ {
if (!sigio_perm(p, fown, fown->signum)) /*
* F_SETSIG can change ->signum lockless in parallel, make
* sure we read it once and use the same value throughout.
*/
int signum = ACCESS_ONCE(fown->signum);
if (!sigio_perm(p, fown, signum))
return; return;
switch (fown->signum) { switch (signum) {
siginfo_t si; siginfo_t si;
default: default:
/* Queue a rt signal with the appropriate fd as its /* Queue a rt signal with the appropriate fd as its
...@@ -444,7 +450,7 @@ static void send_sigio_to_task(struct task_struct *p, ...@@ -444,7 +450,7 @@ static void send_sigio_to_task(struct task_struct *p,
delivered even if we can't queue. Failure to delivered even if we can't queue. Failure to
queue in this case _should_ be reported; we fall queue in this case _should_ be reported; we fall
back to SIGIO in that case. --sct */ back to SIGIO in that case. --sct */
si.si_signo = fown->signum; si.si_signo = signum;
si.si_errno = 0; si.si_errno = 0;
si.si_code = reason; si.si_code = reason;
/* Make sure we are called with one of the POLL_* /* Make sure we are called with one of the POLL_*
...@@ -456,7 +462,7 @@ static void send_sigio_to_task(struct task_struct *p, ...@@ -456,7 +462,7 @@ static void send_sigio_to_task(struct task_struct *p,
else else
si.si_band = band_table[reason - POLL_IN]; si.si_band = band_table[reason - POLL_IN];
si.si_fd = fd; si.si_fd = fd;
if (!group_send_sig_info(fown->signum, &si, p)) if (!group_send_sig_info(signum, &si, p))
break; break;
/* fall-through: fall back on the old plain SIGIO signal */ /* fall-through: fall back on the old plain SIGIO signal */
case 0: case 0:
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment