lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:	Sun, 29 Nov 2009 16:34:48 +0200
From:	Avi Kivity <>
To:	Ingo Molnar <>, "H. Peter Anvin" <>
Subject: [PATCH tip:x86/entry] core: fix user return notifier on fork()

fork() clones all thread_info flags, including TIF_USER_RETURN_NOTIFY; if the
new task is first scheduled on a cpu which doesn't have user return notifiers
set, this causes user return notifiers to trigger without any way of clearing

This is easy to trigger with a forky workload on the host in parallel with
kvm, resulting in a cpu in an endless loop on the verge of returning to

Fix by dropping the TIF_USER_RETURN_NOTIFY immediately after fork.

Signed-off-by: Avi Kivity <>
 include/linux/user-return-notifier.h |    7 +++++++
 kernel/fork.c                        |    2 ++
 2 files changed, 9 insertions(+), 0 deletions(-)

diff --git a/include/linux/user-return-notifier.h b/include/linux/user-return-notifier.h
index b6ac056..9c4a445 100644
--- a/include/linux/user-return-notifier.h
+++ b/include/linux/user-return-notifier.h
@@ -26,6 +26,11 @@ static inline void propagate_user_return_notify(struct task_struct *prev,
 void fire_user_return_notifiers(void);
+static inline void clear_user_return_notifier(struct task_struct *p)
+	clear_tsk_thread_flag(p, TIF_USER_RETURN_NOTIFY);
 struct user_return_notifier {};
@@ -37,6 +42,8 @@ static inline void propagate_user_return_notify(struct task_struct *prev,
 static inline void fire_user_return_notifiers(void) {}
+static inline void clear_user_return_notifier(struct task_struct *p) {}
diff --git a/kernel/fork.c b/kernel/fork.c
index 166b8c4..7d4a348 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -64,6 +64,7 @@
 #include <linux/magic.h>
 #include <linux/perf_event.h>
 #include <linux/posix-timers.h>
+#include <linux/user-return-notifier.h>
 #include <asm/pgtable.h>
 #include <asm/pgalloc.h>
@@ -249,6 +250,7 @@ static struct task_struct *dup_task_struct(struct task_struct *orig)
 		goto out;
 	setup_thread_stack(tsk, orig);
+	clear_user_return_notifier(tsk);
 	stackend = end_of_stack(tsk);
 	*stackend = STACK_END_MAGIC;	/* for overflow detection */

To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to
More majordomo info at
Please read the FAQ at

Powered by blists - more mailing lists