From f8bf15febcaf137bbec5a61101e88cd5a9d56ca8 Mon Sep 17 00:00:00 2001 From: Carlos O'Donell Date: Sat, 28 Jan 2017 19:13:34 -0500 Subject: Bug 20116: Fix use after free in pthread_create() The commit documents the ownership rules around 'struct pthread' and when a thread can read or write to the descriptor. With those ownership rules in place it becomes obvious that pd->stopped_start should not be touched in several of the paths during thread startup, particularly so for detached threads. In the case of detached threads, between the time the thread is created by the OS kernel and the creating thread checks pd->stopped_start, the detached thread might have already exited and the memory for pd unmapped. As a regression test we add a simple test which exercises this exact case by quickly creating detached threads with large enough stacks to ensure the thread stack cache is bypassed and the stacks are unmapped. Before the fix the testcase segfaults, after the fix it works correctly and completes without issue. For a detailed discussion see: https://www.sourceware.org/ml/libc-alpha/2017-01/msg00505.html --- support/xpthread_attr_destroy.c | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 support/xpthread_attr_destroy.c (limited to 'support/xpthread_attr_destroy.c') diff --git a/support/xpthread_attr_destroy.c b/support/xpthread_attr_destroy.c new file mode 100644 index 0000000000..664c809e9f --- /dev/null +++ b/support/xpthread_attr_destroy.c @@ -0,0 +1,26 @@ +/* pthread_attr_destroy with error checking. + Copyright (C) 2017 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +void +xpthread_attr_destroy (pthread_attr_t *attr) +{ + xpthread_check_return ("pthread_attr_destroy", + pthread_attr_destroy (attr)); +} -- cgit v1.2.3-70-g09d2