mirror of
https://github.com/torvalds/linux.git
synced 2026-07-31 03:27:03 +02:00
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()
dereferences p->comm and p->pid. If the iterator's reference is the last
drop, the task is freed synchronously and the deref becomes a UAF.
Move put_task_struct() past scx_error().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260511214031.AF5E9C2BCB0@smtp.kernel.org/
Fixes: f0e1a0643a ("sched_ext: Implement BPF extensible scheduler class")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Tejun Heo <tj@kernel.org>
This commit is contained in:
parent
86ecb1c1a1
commit
9a415cc537
|
|
@ -6973,10 +6973,10 @@ static void scx_root_enable_workfn(struct kthread_work *work)
|
||||||
if (scx_get_task_state(p) != SCX_TASK_DEAD)
|
if (scx_get_task_state(p) != SCX_TASK_DEAD)
|
||||||
scx_set_task_state(p, SCX_TASK_NONE);
|
scx_set_task_state(p, SCX_TASK_NONE);
|
||||||
task_rq_unlock(rq, p, &rf);
|
task_rq_unlock(rq, p, &rf);
|
||||||
put_task_struct(p);
|
|
||||||
scx_task_iter_stop(&sti);
|
scx_task_iter_stop(&sti);
|
||||||
scx_error(sch, "ops.init_task() failed (%d) for %s[%d]",
|
scx_error(sch, "ops.init_task() failed (%d) for %s[%d]",
|
||||||
ret, p->comm, p->pid);
|
ret, p->comm, p->pid);
|
||||||
|
put_task_struct(p);
|
||||||
goto err_disable_unlock_all;
|
goto err_disable_unlock_all;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user