All of lore.kernel.org
 help / color / mirror / Atom feed
* [LTP] [PATCH v6 0/3] Reproducer for ghostlock
@ 2026-09-03  7:26 Andrea Cervesato
  2026-09-03  7:26 ` [LTP] [PATCH v6 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Andrea Cervesato @ 2026-09-03  7:26 UTC (permalink / raw)
  To: Linux Test Project

Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the
rtmutex PI code, fixed in kernel v7.1:
3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")

Reproducer based on the Nebula Security writeup and open-sourced PoC
(https://nebusec.ai/research/ionstack-part-2/, https://github.com/NebuSec/CyberMeowfia).
Beware, this test will crash the system on a vulnerable kernel.

Assisted by Kimi K3 for the analysis and written mostly with Gemini Pro
3.1 Max.

Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
Changes in v6:
- drop const from sched_setattr() and safe_sched_setattr() prototypes to match glibc 2.41+
- add kernel-doc comment for SAFE_SCHED_SETATTR()
- fix struct prctl_mm_map fallback guard in lapi/prctl.h
- validate futex_wait_requeue_pi() outcome before waking spray checkpoint
- sort ghostlock entry in testcases/cve/.gitignore
- Link to v5: https://lore.kernel.org/20260902-cve-ghostlock-v5-0-569b9eb37941@suse.com

Changes in v5:
- reduced synchronization checkpoints from 5 to 3
- introduced and used SAFE_SCHED_SETATTR() in lapi/sched.h
- dropped unused PR_SET_MM_MAP_SIZE probe in setup()
- fixed duplicated -pthread entry in Makefile
- fixed CVE numerical ordering in runtest/cve
- Link to v4: https://lore.kernel.org/20260826-cve-ghostlock-v4-0-52ec94d6635f@suse.com

Changes in v4:
- handle runtime inside the test
- increase futext wait so we don't TBROK before runtime
- comment prctl() syscall
- move static vars out of the run function
- Link to v3: https://lore.kernel.org/20260803-cve-ghostlock-v3-0-cde83fa429b7@suse.com

Changes in v3:
- improve sync mechanism
- fix lapi imports
- Link to v2: https://lore.kernel.org/20260803-cve-ghostlock-v2-0-b60588853140@suse.com

Changes in v2:
- fix build
- fix 32bit run
- Link to v1: https://lore.kernel.org/20260801-cve-ghostlock-v1-0-178f698f9702@suse.com

---
Andrea Cervesato (3):
      lapi/sched: add SAFE_SCHED_SETATTR()
      lapi/prctl: add more fallback definitions
      cve: add CVE-2026-43499 reproducer

 configure.ac              |   2 +
 include/lapi/prctl.h      |  26 +++++
 include/lapi/sched.h      |  31 +++++-
 runtest/cve               |   1 +
 testcases/cve/.gitignore  |   1 +
 testcases/cve/Makefile    |   2 +-
 testcases/cve/ghostlock.c | 246 ++++++++++++++++++++++++++++++++++++++++++++++
 7 files changed, 307 insertions(+), 2 deletions(-)
---
base-commit: 12724413534a6d4160ff9694ba6f09daa4ccb6bd
change-id: 20260801-cve-ghostlock-6ee4b2f69fd6

Best regards,
--  
Andrea Cervesato <andrea.cervesato@suse.com>


-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

^ permalink raw reply	[flat|nested] 8+ messages in thread
* [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR()
@ 2026-09-02 21:25 Andrea Cervesato
  2026-09-02 23:07 ` [LTP] " linuxtestproject.agent
  0 siblings, 1 reply; 8+ messages in thread
From: Andrea Cervesato @ 2026-09-02 21:25 UTC (permalink / raw)
  To: Linux Test Project

From: Andrea Cervesato <andrea.cervesato@suse.com>

Add a safe variant of sched_setattr() that breaks the test with TBROK
on failure, so tests such as the CVE-2026-43499 reproducer do not have
to open-code the TEST() + tst_brk() error handling.

Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
 include/lapi/sched.h | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/include/lapi/sched.h b/include/lapi/sched.h
index 05b322c1c..6b49a1cda 100644
--- a/include/lapi/sched.h
+++ b/include/lapi/sched.h
@@ -169,4 +169,23 @@ static inline int getcpu(unsigned *cpu, unsigned *node)
 # define CLONE_INTO_CGROUP 0x200000000ULL
 #endif
 
+static inline int safe_sched_setattr(const char *file, const int lineno,
+				     pid_t pid, const struct sched_attr *attr,
+				     unsigned int flags)
+{
+	int ret;
+
+	ret = sched_setattr(pid, attr, flags);
+
+	if (ret == -1) {
+		tst_brk_(file, lineno, TBROK | TERRNO,
+			"sched_setattr(%i) failed", pid);
+	}
+
+	return ret;
+}
+
+#define SAFE_SCHED_SETATTR(pid, attr, flags)\
+	safe_sched_setattr(__FILE__, __LINE__, (pid), (attr), (flags))
+
 #endif /* LAPI_SCHED_H__ */

-- 
2.51.0


-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-03 12:02 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03  7:26 [LTP] [PATCH v6 0/3] Reproducer for ghostlock Andrea Cervesato
2026-09-03  7:26 ` [LTP] [PATCH v6 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
2026-09-03  7:38   ` Andrea Cervesato via ltp
2026-09-03 12:02   ` [LTP] " linuxtestproject.agent
2026-09-03  7:26 ` [LTP] [PATCH v6 2/3] lapi/prctl: add more fallback definitions Andrea Cervesato
2026-09-03  7:26 ` [LTP] [PATCH v6 3/3] cve: add CVE-2026-43499 reproducer Andrea Cervesato
  -- strict thread matches above, loose matches on Subject: below --
2026-09-02 21:25 [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
2026-09-02 23:07 ` [LTP] " linuxtestproject.agent
2026-09-03  7:14   ` Andrea Cervesato via ltp

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.