aboutsummaryrefslogtreecommitdiff
path: root/lib/libblocklist/(developers-only)
diff options
context:
space:
mode:
authorOlivier Certner <olce@FreeBSD.org>2026-09-25 17:27:25 +0000
committerOlivier Certner <olce@FreeBSD.org>2026-09-30 09:05:02 +0000
commite6fbef451dd45159071a1b234cd13c66fbb654fa (patch)
tree9a38746755cbe60c434490e62ba96415e7b7e17b /lib/libblocklist/(developers-only)
parent2447e7773e36bbc89e80294c1e8cb53f9f607762 (diff)
cred: Fix a race in the FreeBSD-14-compatible setgroups(2)HEADmain
The freebsd14_setgroups() function would try to modify the effective GID on the current process' credentials without holding the process lock, allowing races with other threads concurrently modifying the process credentials. In the worst case, freebsd14_setgroups() could be manipulating a 'struct ucred' already freed by another thread (in the very small window after reading 'p_ucred' without lock but before modifying the effective GID). Concurrent uses of freebsd14_setgroups() or setcred() could also lead to non-atomic credentials modifications. Fix this by making kern_setgroups() take a new boolean indicating whether the passed array includes the effective GID in its first slot. When this boolean is true, it internally keeps the effective GID in a separate variable, pretends that the groups[] array that was passed actually starts at 'groups + 1', do the usual steps to set the supplementary groups and new extra ones to set the effective GID along, without releasing the process lock in between. Reported by: markj Reviewed by: markj MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D60028
Diffstat (limited to 'lib/libblocklist/(developers-only)')
0 files changed, 0 insertions, 0 deletions