From: Dmitry Vyukov <dvyukov@google.com>
To: gregkh@linuxfoundation.org, peter@hurleysoftware.com,
jslaby@suse.com, linux-kernel@vger.kernel.org
Cc: jslaby@suse.cz, andreyknvl@google.com, kcc@google.com,
glider@google.com, paulmck@linux.vnet.ibm.com, hboehm@google.com,
Dmitry Vyukov <dvyukov@google.com>
Subject: [PATCH] tty: fix data race in tty_buffer_flush
Date: Mon, 7 Sep 2015 14:26:21 +0200 [thread overview]
Message-ID: <1441628781-73974-1-git-send-email-dvyukov@google.com> (raw)
tty_buffer_flush frees not acquired buffers.
As the result, for example, read of b->size in tty_buffer_free
can return garbage value which will lead to a huge buffer
hanging in the freelist. This is just the benignest
manifestation of freeing of a not acquired object.
If the object is passed to kfree, heap can be corrupted.
Acquire visibility over the buffer before freeing it.
The data race was found with KernelThreadSanitizer (KTSAN).
Signed-off-by: Dmitry Vyukov <dvyukov@google.com>
---
drivers/tty/tty_buffer.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/tty/tty_buffer.c b/drivers/tty/tty_buffer.c
index 5a3fa89..7dab1b3 100644
--- a/drivers/tty/tty_buffer.c
+++ b/drivers/tty/tty_buffer.c
@@ -242,7 +242,7 @@ void tty_buffer_flush(struct tty_struct *tty, struct tty_ldisc *ld)
atomic_inc(&buf->priority);
mutex_lock(&buf->lock);
- while ((next = buf->head->next) != NULL) {
+ while ((next = smp_load_acquire(&buf->head->next)) != NULL) {
tty_buffer_free(port, buf->head);
buf->head = next;
}
--
2.5.0.457.gab17608
next reply other threads:[~2015-09-07 12:26 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-09-07 12:26 Dmitry Vyukov [this message]
2015-09-08 12:48 ` Dmitry Vyukov
2015-09-08 22:11 ` Greg KH
2015-09-16 1:38 ` Peter Hurley
2015-09-16 18:20 ` Dmitry Vyukov
2015-09-17 10:28 ` Dmitry Vyukov
2015-09-17 10:59 ` Dmitry Vyukov
2015-09-17 12:51 ` Greg Kroah-Hartman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1441628781-73974-1-git-send-email-dvyukov@google.com \
--to=dvyukov@google.com \
--cc=andreyknvl@google.com \
--cc=glider@google.com \
--cc=gregkh@linuxfoundation.org \
--cc=hboehm@google.com \
--cc=jslaby@suse.com \
--cc=jslaby@suse.cz \
--cc=kcc@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=paulmck@linux.vnet.ibm.com \
--cc=peter@hurleysoftware.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®