Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1274886

Re: Use-after-free in ppoll

From Dmitry Vyukov <dvyukov@google.com>
Newsgroups linux.kernel
Subject Re: Use-after-free in ppoll
Date 2015-11-22 15:50 +0100
Message-ID <qxE7L-57v-1@gated-at.bofh.it> (permalink)
References <qxDEJ-4UZ-3@gated-at.bofh.it> <qxDY5-51Z-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sun, Nov 22, 2015 at 3:32 PM, Rainer Weikusat
<rweikusat@mobileactivedefense.com> wrote:
> Dmitry Vyukov <dvyukov@google.com> writes:
>> Hello,
>>
>> On commit f2d10565b9bdbb722bd43e6e1a759eeddb9645c8 (Nov 20).
>>
>> The following program triggers use-after-free:
>>
>> // autogenerated by syzkaller (http://github.com/google/syzkaller)
>> #include <syscall.h>
>> #include <string.h>
>> #include <stdint.h>
>> #include <pthread.h>
>>
>> void *thread(void *p)
>> {
>>         syscall(SYS_write, (long)p, 0x2000278ful, 0x1ul, 0, 0, 0);
>>         return 0;
>> }
>
> [...]
>
>
>>         long r1 = syscall(SYS_socketpair, 0x1ul, 0x3ul, 0x0ul,
>
> [...]
>
>>         long r5 = syscall(SYS_close, r2, 0, 0, 0, 0, 0);
>>         pthread_t th;
>>         pthread_create(&th, 0, thread, (void*)(long)r3);
>
> [...]
>
>>         long r21 = syscall(SYS_ppoll, 0x20000ffful, 0x3ul, 0x20000ffcul, 0x20000ffdul, 0x8ul, 0);
>>         return 0;
>> }
>
> That's one of the already known sequences for triggering this issue: The
> close will clear the peer pointer of the closed socket, hence, the 2nd
> sock_poll_wait will be called by unix_dgram_poll. The write will
> execute unix_dgram_sendmsg which detects that the peer is dead and
> disconnects from it, causing the corresponding structures to be freed
> despite they're still used.
>
> NB: I didn't execute this but I spend a fair amount of time with the
> af_unix.c code during the last couple of weeks and consider myself
> "reasonably familiar" with it and that's IMO what should happen here.


I have not read the code. But I just want to point out that all 3
reports are different. For example, in the first one, ppoll both frees
the object and then accesses it. That is, it is not write that frees
the object.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Use-after-free in ppoll Dmitry Vyukov <dvyukov@google.com> - 2015-11-22 15:20 +0100
  Re: Use-after-free in ppoll Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-22 15:40 +0100
    Re: Use-after-free in ppoll Dmitry Vyukov <dvyukov@google.com> - 2015-11-22 15:50 +0100
      Re: Use-after-free in ppoll Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-22 19:50 +0100
        Re: Use-after-free in ppoll Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-22 20:00 +0100
        Re: Use-after-free in ppoll Dmitry Vyukov <dvyukov@google.com> - 2015-11-23 13:10 +0100

csiph-web