Thread (31 messages) 31 messages, 4 authors, 2019-01-16

Re: KASAN: use-after-free Read in task_is_descendant

From: Kees Cook <hidden>
Date: 2018-10-26 16:09:25
Also in: lkml

On Thu, Oct 25, 2018 at 2:01 PM, Oleg Nesterov [off-list ref] wrote:
On 10/25, Oleg Nesterov wrote:
quoted
perhaps it needs some changes too. I even have a vague feeling that I have already
blamed this function some time ago...
Heh, yes, 3 years ago ;)

https://lore.kernel.org/lkml/20150106184427.GA18153@redhat.com/ (local)

I can't understand my email today, but note that I tried to point out that
task_is_descendant() can dereference the freed mem.
Instead of:

        while (walker->pid > 0) {

should it simply be "while (pid_liave(walker)) {"? And add a
pid_alive(parent) after rcu_read_lock()?
And yes, task_is_descendant() is overcompicated for no reason, afaics.
Yeah, agreed. I'll fix this up. Just to make sure I'm not crazy: the
real_parent of all tasks in a thread group are the same, yes? The
trouble I was trying to deal with for the complication was where a
non-leader thread would add an exception to the checking, and the
tasks wouldn't match. (As far as I can see, though, using
same_thread_group() should fix it.)

-Kees

-- 
Kees Cook
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help