Tycho Andersen
0506d711a3
UPSTREAM: seccomp: don't leak memory when filter install races
...
In seccomp_set_mode_filter() with TSYNC | NEW_LISTENER, we first initialize
the listener fd, then check to see if we can actually use it later in
seccomp_may_assign_mode(), which can fail if anyone else in our thread
group has installed a filter and caused some divergence. If we can't, we
partially clean up the newly allocated file: we put the fd, put the file,
but don't actually clean up the *memory* that was allocated at
filter->notif. Let's clean that up too.
To accomplish this, let's hoist the actual "detach a notifier from a
filter" code to its own helper out of seccomp_notify_release(), so that in
case anyone adds stuff to init_listener(), they only have to add the
cleanup code in one spot. This does a bit of extra locking and such on the
failure path when the filter is not attached, but it's a slow failure path
anyway.
Fixes: 51891498f2da ("seccomp: allow TSYNC and USER_NOTIF together")
Reported-by: syzbot+3ad9614a12f80994c32e@syzkaller.appspotmail.com
Signed-off-by: Tycho Andersen <tycho@tycho.pizza>
Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Link: https://lore.kernel.org/r/20200902014017.934315-1-tycho@tycho.pizza
Signed-off-by: Kees Cook <keescook@chromium.org>
(cherry picked from commit a566a9012acd7c9a4be7e30dc7acb7a811ec2260)
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Bug: 176068146
Change-Id: I8e6ce0f1646ff997623458f25b733ba79c0a47a2
2026-05-07 10:17:17 -04:00
..
bpf
UPSTREAM: bpf, netns: Fix build without CONFIG_INET
2026-01-14 18:13:18 -08:00
cgroup
UPSTREAM: cgroup: remove redundant kernfs_activate in cgroup_setup_root()
2026-01-14 18:13:14 -08:00
configs
debug
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
dma
Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-10-09 18:08:17 +00:00
events
UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work
2026-01-14 18:12:08 -08:00
gcov
gcov: add support for GCC 15
2025-12-03 12:45:19 +01:00
irq
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:23:13 +03:00
livepatch
UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag
2025-12-23 13:35:45 -08:00
locking
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-06-30 10:49:17 +03:00
power
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:17:54 +03:00
printk
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
rcu
BACKPORT: rcu-tasks: Add a grace-period start time for throttling and debug
2026-01-14 18:13:22 -08:00
sched
UPSTREAM: sched/core: Add function to sample state of locked-down task
2026-01-14 18:13:18 -08:00
time
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
trace
UPSTREAM: bpf: Fix passing zero to PTR_ERR() in bpf_btf_printf_prepare
2026-02-01 20:44:47 -08:00
.gitignore
acct.c
acct: perform last write from workqueue
2025-03-13 12:43:26 +01:00
async.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
audit.c
audit: Send netlink ACK before setting connection in auditd_set
2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c
audit: fix possible soft lockup in __audit_inode_child()
2023-09-23 10:59:46 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-04-20 12:07:32 +02:00
bounds.c
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c
hrtimers: Handle CPU state correctly on hotplug
2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
Revert "cred: switch to using atomic_long_t"
2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c
BACKPORT: seccomp: release filter after task is fully dead
2026-05-07 10:17:17 -04:00
extable.c
UPSTREAM: bpf: Remove bpf_image tree
2025-12-23 13:36:07 -08:00
fail_function.c
kernel/fail_function: fix memory leak with using debugfs_lookup()
2023-03-11 16:44:15 +01:00
fork.c
BACKPORT: seccomp: release filter after task is fully dead
2026-05-07 10:17:17 -04:00
freezer.c
futex.c
Merge 5.4.246 into android11-5.4-lts
2023-06-20 19:13:58 +00:00
gen_kheaders.sh
Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina
2025-04-12 09:31:28 +00:00
groups.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
hung_task.c
kernel/hung_task.c: make type annotations consistent
2026-02-01 20:38:49 -08:00
iomem.c
irq_work.c
UPSTREAM: irq_work: Convert flags to atomic_t
2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: fix a memory leak in crash_shrink_memory()
2023-07-27 08:37:10 +02:00
kexec_elf.c
kexec: initialize ELF lowest address to ULONG_MAX
2025-04-10 14:29:41 +02:00
kexec_file.c
kexec: support purgatories with .text.hot sections
2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c
kheaders: Use array declaration instead of char
2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
latencytop.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
Makefile
UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs.
2026-01-14 18:12:16 -08:00
module-internal.h
module.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c
padata: Reset next CPU when reorder sequence wraps around
2025-10-29 14:00:01 +01:00
panic.c
panic: Flush kernel log buffer at the end
2024-04-13 12:51:37 +02:00
params.c
module: ensure that kobject_put() is safe for module type kobjects
2025-06-04 14:32:27 +02:00
pid.c
Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-12-04 19:21:35 +02:00
pid_namespace.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
profile.c
ptrace.c
range.c
reboot.c
This is the 5.4.262 stable release
2023-11-29 10:18:14 +00:00
relay.c
relayfs: fix out-of-bounds access in relay_file_read
2023-05-17 11:35:58 +02:00
resource.c
resource: fix region_intersects() vs add_memory_driver_managed()
2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c
UPSTREAM: seccomp: don't leak memory when filter install races
2026-05-07 10:17:17 -04:00
signal.c
Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-12-17 03:24:53 +02:00
smp.c
Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c
Revert "tasklet: Introduce new initialization API"
2025-03-13 17:21:46 +00:00
stackleak.c
stackleak: let stack_erasing_sysctl take a kernel pointer buffer
2026-02-01 20:38:37 -08:00
stacktrace.c
stop_machine.c
sys.c
Merge 5.4.272 into android11-5.4-lts
2024-04-05 12:37:33 +00:00
sys_ni.c
BACKPORT: epoll: wire up syscall epoll_pwait2
2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c
bpf, sysctl: Let bpf_stats_handler take a kernel pointer buffer
2026-02-01 20:37:19 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
UPSTREAM: module: Fix up module_notifier return values
2026-01-14 18:12:53 -08:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
BACKPORT: umh: Separate the user mode driver and the user mode helper support
2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c
UPSTREAM: bpf: Fix umd memory leak in copy_process()
2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog_hld.c
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
2024-08-19 05:33:39 +02:00
workqueue.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
workqueue_internal.h