All of lore.kernel.org
 help / color / mirror / Atom feed
* buggy check in netlink_mmap_sendmsg()
@ 2013-07-14  9:36 Al Viro
  2013-07-18 11:22 ` Patrick McHardy
  0 siblings, 1 reply; 5+ messages in thread
From: Al Viro @ 2013-07-14  9:36 UTC (permalink / raw)
  To: Patrick McHardy; +Cc: netdev

This
        /* Netlink messages are validated by the receiver before processing.
         * In order to avoid userspace changing the contents of the message
         * after validation, the socket and the ring may only be used by a
         * single process, otherwise we fall back to copying.
         */
        if (atomic_long_read(&sk->sk_socket->file->f_count) > 2 ||  
            atomic_read(&nlk->mapped) > 1)
                excl = false;
looks very odd.  For one thing, descriptor table may be shared, with
one thread calling sendmsg() (which gives f_count equal to 2), while
another calls mmap() just as the first one gets past that check.
Moreover, we might very well have the damn thing mmapped, then clone(2)
creating another thread that shares address space, but not the descriptor
table.  Child closes the socket descriptor it got, then parent does
sendmsg(2) (f_count == 2, again, since this time descriptor table isn't
shared and sendmsg(2) doesn't grab a reference and we have 1 from descriptor
table and 1 from mapping).  Again, the child has it mapped and can play
with it as it wishes...

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2013-07-19 15:52 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-07-14  9:36 buggy check in netlink_mmap_sendmsg() Al Viro
2013-07-18 11:22 ` Patrick McHardy
2013-07-19 15:38   ` Patrick McHardy
2013-07-19 15:45     ` Al Viro
2013-07-19 15:52     ` Al Viro

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.