lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Fri, 28 Oct 2022 13:56:46 -0700 From: Dexuan Cui <decui@...rosoft.com> To: sgarzare@...hat.com, davem@...emloft.net, edumazet@...gle.com, kuba@...nel.org, pabeni@...hat.com, arseny.krasnov@...persky.com, netdev@...r.kernel.org Cc: virtualization@...ts.linux-foundation.org, linux-kernel@...r.kernel.org, kys@...rosoft.com, haiyangz@...rosoft.com, stephen@...workplumber.org, wei.liu@...nel.org, linux-hyperv@...r.kernel.org, Dexuan Cui <decui@...rosoft.com> Subject: [PATCH 2/2] vsock: fix possible infinite sleep in vsock_connectible_wait_data() Currently vsock_connectible_has_data() may miss a wakeup operation between vsock_connectible_has_data() == 0 and the prepare_to_wait(). Fix the race by adding the process to the wait qeuue before checking vsock_connectible_has_data(). Fixes: b3f7fd54881b ("af_vsock: separate wait data loop") Signed-off-by: Dexuan Cui <decui@...rosoft.com> --- net/vmw_vsock/af_vsock.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index d258fd43092e..03a6b5bc6ba7 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -1905,8 +1905,11 @@ static int vsock_connectible_wait_data(struct sock *sk, err = 0; transport = vsk->transport; - while ((data = vsock_connectible_has_data(vsk)) == 0) { + while (1) { prepare_to_wait(sk_sleep(sk), wait, TASK_INTERRUPTIBLE); + data = vsock_connectible_has_data(vsk); + if (data != 0) + break; if (sk->sk_err != 0 || (sk->sk_shutdown & RCV_SHUTDOWN) || @@ -1937,6 +1940,8 @@ static int vsock_connectible_wait_data(struct sock *sk, err = -EAGAIN; break; } + + finish_wait(sk_sleep(sk), wait); } finish_wait(sk_sleep(sk), wait); -- 2.25.1
Powered by blists - more mailing lists