aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-08-24 18:14:18 +0000
committerMark Johnston <markj@FreeBSD.org>2026-08-25 15:47:13 +0000
commitc7cec6fa6e4aeca7488130e17f4fd1ad2c476fa0 (patch)
treeed6fddcdbe379b882d00c30f125ca7b86f4da268
parentc5ad29cb6c62fb50164e953ea5ad017350db875c (diff)
tty: Revalidate after dropping the tty lock in ioctl handlers
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the proctree relock. After relocking the tty, it did not revalidate the tty state, and it could end up linking a doomed tty to the calling process' session. This race can be exploited to escalate privileges. TIOCSPGRP has a similar race, fix that too. Approved by: so Security: FreeBSD-SA-26:62.tty Security: CVE-2026-58093 Reported by: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59126
-rw-r--r--sys/kern/tty.c14
1 files changed, 12 insertions, 2 deletions
diff --git a/sys/kern/tty.c b/sys/kern/tty.c
index 09ed1c6d0c5d..f412205a3d2b 100644
--- a/sys/kern/tty.c
+++ b/sys/kern/tty.c
@@ -1890,7 +1890,12 @@ tty_generic_ioctl(struct tty *tp, u_long cmd, void *data, int fflag,
/* XXX: This looks awful. */
tty_unlock(tp);
sx_xlock(&proctree_lock);
- tty_lock(tp);
+ error = ttydev_enter(tp);
+ if (error != 0) {
+ sx_xunlock(&proctree_lock);
+ tty_lock(tp);
+ return (error);
+ }
if (!SESS_LEADER(p)) {
/* Only the session leader may do this. */
@@ -1954,7 +1959,12 @@ tty_generic_ioctl(struct tty *tp, u_long cmd, void *data, int fflag,
tty_lock(tp);
return (EPERM);
}
- tty_lock(tp);
+ error = ttydev_enter(tp);
+ if (error != 0) {
+ sx_sunlock(&proctree_lock);
+ tty_lock(tp);
+ return (error);
+ }
/*
* Determine if this TTY is the controlling TTY after