svn commit: r351261 - in releng: 11.2/sys/kern 11.3/sys/kern 12.0/sys/kern
Gordon Tetlow
gordon at FreeBSD.org
Tue Aug 20 17:51:34 UTC 2019
Author: gordon
Date: Tue Aug 20 17:51:32 2019
New Revision: 351261
URL: https://svnweb.freebsd.org/changeset/base/351261
Log:
Fix reference count overflow in mqueuefs.
Approved by: so
Security: FreeBSD-SA-19:24.mqueuefs
Security: CVE-2019-5603
Modified:
releng/11.2/sys/kern/uipc_mqueue.c
releng/11.3/sys/kern/uipc_mqueue.c
releng/12.0/sys/kern/uipc_mqueue.c
Modified: releng/11.2/sys/kern/uipc_mqueue.c
==============================================================================
--- releng/11.2/sys/kern/uipc_mqueue.c Tue Aug 20 17:50:33 2019 (r351260)
+++ releng/11.2/sys/kern/uipc_mqueue.c Tue Aug 20 17:51:32 2019 (r351261)
@@ -2788,7 +2788,7 @@ freebsd32_kmq_timedsend(struct thread *td,
if (uap->abs_timeout != NULL) {
error = copyin(uap->abs_timeout, &ets32, sizeof(ets32));
if (error != 0)
- return (error);
+ goto out;
CP(ets32, ets, tv_sec);
CP(ets32, ets, tv_nsec);
abs_timeout = &ets;
@@ -2797,6 +2797,7 @@ freebsd32_kmq_timedsend(struct thread *td,
waitok = !(fp->f_flag & O_NONBLOCK);
error = mqueue_send(mq, uap->msg_ptr, uap->msg_len,
uap->msg_prio, waitok, abs_timeout);
+out:
fdrop(fp, td);
return (error);
}
Modified: releng/11.3/sys/kern/uipc_mqueue.c
==============================================================================
--- releng/11.3/sys/kern/uipc_mqueue.c Tue Aug 20 17:50:33 2019 (r351260)
+++ releng/11.3/sys/kern/uipc_mqueue.c Tue Aug 20 17:51:32 2019 (r351261)
@@ -2788,7 +2788,7 @@ freebsd32_kmq_timedsend(struct thread *td,
if (uap->abs_timeout != NULL) {
error = copyin(uap->abs_timeout, &ets32, sizeof(ets32));
if (error != 0)
- return (error);
+ goto out;
CP(ets32, ets, tv_sec);
CP(ets32, ets, tv_nsec);
abs_timeout = &ets;
@@ -2797,6 +2797,7 @@ freebsd32_kmq_timedsend(struct thread *td,
waitok = !(fp->f_flag & O_NONBLOCK);
error = mqueue_send(mq, uap->msg_ptr, uap->msg_len,
uap->msg_prio, waitok, abs_timeout);
+out:
fdrop(fp, td);
return (error);
}
Modified: releng/12.0/sys/kern/uipc_mqueue.c
==============================================================================
--- releng/12.0/sys/kern/uipc_mqueue.c Tue Aug 20 17:50:33 2019 (r351260)
+++ releng/12.0/sys/kern/uipc_mqueue.c Tue Aug 20 17:51:32 2019 (r351261)
@@ -2798,7 +2798,7 @@ freebsd32_kmq_timedsend(struct thread *td,
if (uap->abs_timeout != NULL) {
error = copyin(uap->abs_timeout, &ets32, sizeof(ets32));
if (error != 0)
- return (error);
+ goto out;
CP(ets32, ets, tv_sec);
CP(ets32, ets, tv_nsec);
abs_timeout = &ets;
@@ -2807,6 +2807,7 @@ freebsd32_kmq_timedsend(struct thread *td,
waitok = !(fp->f_flag & O_NONBLOCK);
error = mqueue_send(mq, uap->msg_ptr, uap->msg_len,
uap->msg_prio, waitok, abs_timeout);
+out:
fdrop(fp, td);
return (error);
}
More information about the svn-src-releng
mailing list