Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1227240

Re: [PATCH v5 2/3] tty: fix data race in tty_buffer_flush

From Peter Hurley <peter@hurleysoftware.com>
Newsgroups linux.kernel
Subject Re: [PATCH v5 2/3] tty: fix data race in tty_buffer_flush
Date 2015-09-17 19:40 +0200
Message-ID <q9Lk6-286-29@gated-at.bofh.it> (permalink)
References <q9J8C-7rl-19@gated-at.bofh.it> <q9J8D-7rl-45@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, Sep 17, 2015 at 11:17 AM, Dmitry Vyukov <dvyukov@google.com> wrote:
> tty_buffer_flush frees not acquired buffers.
> As the result, for example, read of b->size in tty_buffer_free
> can return garbage value which will lead to a huge buffer
> hanging in the freelist. This is just the benignest
> manifestation of freeing of a not acquired object.
> If the object is passed to kfree, heap can be corrupted.
>
> Acquire visibility over the buffer before freeing it.
>
> The data race was found with KernelThreadSanitizer (KTSAN).

Reviewed-by: Peter Hurley <peter@hurleysoftware.com>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH v5 2/3] tty: fix data race in tty_buffer_flush Dmitry Vyukov <dvyukov@google.com> - 2015-09-17 17:20 +0200
  Re: [PATCH v5 2/3] tty: fix data race in tty_buffer_flush Peter Hurley <peter@hurleysoftware.com> - 2015-09-17 19:40 +0200

csiph-web