Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1227240
| From | Peter Hurley <peter@hurleysoftware.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v5 2/3] tty: fix data race in tty_buffer_flush |
| Date | 2015-09-17 19:40 +0200 |
| Message-ID | <q9Lk6-286-29@gated-at.bofh.it> (permalink) |
| References | <q9J8C-7rl-19@gated-at.bofh.it> <q9J8D-7rl-45@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Thu, Sep 17, 2015 at 11:17 AM, Dmitry Vyukov <dvyukov@google.com> wrote: > tty_buffer_flush frees not acquired buffers. > As the result, for example, read of b->size in tty_buffer_free > can return garbage value which will lead to a huge buffer > hanging in the freelist. This is just the benignest > manifestation of freeing of a not acquired object. > If the object is passed to kfree, heap can be corrupted. > > Acquire visibility over the buffer before freeing it. > > The data race was found with KernelThreadSanitizer (KTSAN). Reviewed-by: Peter Hurley <peter@hurleysoftware.com> -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH v5 2/3] tty: fix data race in tty_buffer_flush Dmitry Vyukov <dvyukov@google.com> - 2015-09-17 17:20 +0200 Re: [PATCH v5 2/3] tty: fix data race in tty_buffer_flush Peter Hurley <peter@hurleysoftware.com> - 2015-09-17 19:40 +0200
csiph-web