lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Wed, 02 Sep 2020 17:46:58 +0200
From:   Takashi Iwai <tiwai@...e.de>
To:     Al Viro <viro@...iv.linux.org.uk>
Cc:     maz@...nel.org, alsa-devel@...a-project.org,
        dan.carpenter@...cle.com, linux-fsdevel@...r.kernel.org,
        linux-kernel@...r.kernel.org, o-takashi@...amocchi.jp,
        perex@...ex.cz, syzkaller-bugs@...glegroups.com, tiwai@...e.com
Subject: Re: general protection fault in snd_ctl_release

On Wed, 02 Sep 2020 17:35:30 +0200,
Al Viro wrote:
> 
> On Wed, Sep 02, 2020 at 05:22:00PM +0200, Takashi Iwai wrote:
> 
> > Marc, Al, could you guys check this bug?
> 
> That's racy; the first one should be get_file_rcu() instead of
> file_count()+get_file(), the second is not needed at all (we
> have the file pinned down by the caller).

Yeah, that wasn't meant as a fix, of course :)


> See vfs.git#work.epoll
> for fix

Thanks!  I'll try to run with this fix.


Takashi

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ