diff options
| author | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-30 13:41:53 +0000 |
|---|---|---|
| committer | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-30 13:51:18 +0000 |
| commit | dd5dc8f6e51c5132f2dc885f5c1b0492cdf3052c (patch) | |
| tree | da57a766d8b51a478936fcbdf24d11ab2998bf1a /packages/powerd/(public-mirror) | |
| parent | 005af8327476d12a881e54bc800dbafa73c8a866 (diff) | |
epoch_trace_report() assigned the return value of RB_INSERT() back to
the new element. When two threads report the same stack concurrently,
the loser's RB_INSERT() returns the element already in the tree, and
that element was freed while still linked, leaking the new allocation.
The next lookup touches freed memory; KASAN catches it as a
use-after-free.
Keep the return value separate and free the new element instead. The
thread that won the race prints the report, so return without printing
it a second time.
Reviewed by: markj
Fixes: 173c062a569b ("Improve EPOCH_TRACE")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60162
Diffstat (limited to 'packages/powerd/(public-mirror)')
0 files changed, 0 insertions, 0 deletions
