summaryrefslogtreecommitdiff
path: root/include/drm
diff options
context:
space:
mode:
authorJann Horn <jannh@google.com>2018-10-01 17:31:17 +0200
committerDaniel Vetter <daniel.vetter@ffwll.ch>2018-10-02 10:22:10 +0200
commit12d43deb1ee639d01a2a8d2a7a4cc8ad31224475 (patch)
treec0f54d0c9c1c10852232a0bbb5753dad6fd13f38 /include/drm
parent17b57b1883c1285f3d0dc2266e8f79286a7bef38 (diff)
drm: fix use-after-free read in drm_mode_create_lease_ioctl()
fd_install() moves the reference given to it into the file descriptor table of the current process. If the current process is multithreaded, then immediately after fd_install(), another thread can close() the file descriptor and cause the file's resources to be cleaned up. Since the reference to "lessee" is held by the file, we must not access "lessee" after the fd_install() call. As far as I can tell, to reach this codepath, the caller must have an open file descriptor to a DRI device in master mode. I'm not sure what the requirements for that are. Signed-off-by: Jann Horn <jannh@google.com> Fixes: 62884cd386b8 ("drm: Add four ioctls for managing drm mode object leases [v7]") Cc: stable@vger.kernel.org Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch> Link: https://patchwork.freedesktop.org/patch/msgid/20181001153117.216923-1-jannh@google.com
Diffstat (limited to 'include/drm')
0 files changed, 0 insertions, 0 deletions