git: c7cec6fa6e4a - stable/15 - tty: Revalidate after dropping the tty lock in ioctl handlers
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 25 Aug 2026 15:59:52 UTC
The branch stable/15 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=c7cec6fa6e4aeca7488130e17f4fd1ad2c476fa0
commit c7cec6fa6e4aeca7488130e17f4fd1ad2c476fa0
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-08-24 18:14:18 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-08-25 15:47:13 +0000
tty: Revalidate after dropping the tty lock in ioctl handlers
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the
proctree relock. After relocking the tty, it did not revalidate the
tty state, and it could end up linking a doomed tty to the calling
process' session. This race can be exploited to escalate privileges.
TIOCSPGRP has a similar race, fix that too.
Approved by: so
Security: FreeBSD-SA-26:62.tty
Security: CVE-2026-58093
Reported by: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59126
---
sys/kern/tty.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/sys/kern/tty.c b/sys/kern/tty.c
index 09ed1c6d0c5d..f412205a3d2b 100644
--- a/sys/kern/tty.c
+++ b/sys/kern/tty.c
@@ -1890,7 +1890,12 @@ tty_generic_ioctl(struct tty *tp, u_long cmd, void *data, int fflag,
/* XXX: This looks awful. */
tty_unlock(tp);
sx_xlock(&proctree_lock);
- tty_lock(tp);
+ error = ttydev_enter(tp);
+ if (error != 0) {
+ sx_xunlock(&proctree_lock);
+ tty_lock(tp);
+ return (error);
+ }
if (!SESS_LEADER(p)) {
/* Only the session leader may do this. */
@@ -1954,7 +1959,12 @@ tty_generic_ioctl(struct tty *tp, u_long cmd, void *data, int fflag,
tty_lock(tp);
return (EPERM);
}
- tty_lock(tp);
+ error = ttydev_enter(tp);
+ if (error != 0) {
+ sx_sunlock(&proctree_lock);
+ tty_lock(tp);
+ return (error);
+ }
/*
* Determine if this TTY is the controlling TTY after