git: 718746766c18 - stable/14 - proc: free kstack buffers when debug permission changes
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 28 Sep 2026 16:20:34 UTC
The branch stable/14 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=718746766c18130f06602f1625d05ac514bb84a2
commit 718746766c18130f06602f1625d05ac514bb84a2
Author: Andrew Griffiths <andrew@calif.io>
AuthorDate: 2026-09-14 07:55:01 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-28 13:38:23 +0000
proc: free kstack buffers when debug permission changes
The kern.proc.kstack handler allocates its output and stack buffers
before deliberately checking p_candebug again under the process lock.
If trace-control state changes between authorization checks, the failure
path balances the process and exec state but leaks both buffers.
Submitted by calif.io for the OpenAI Patch The Planet program
Signed-off-by: Andrew Griffiths <andrew@calif.io>
Fixes: 8b5abd9027b8 ("kern_proc.c: disallow execve around sysctl kern.proc.kstacks")
Reviewed by: markj
MFC after: 1 week
(cherry picked from commit 3484217cc47c1f77d2be2ed0e012b870d1cd3dca)
---
sys/kern/kern_proc.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sys/kern/kern_proc.c b/sys/kern/kern_proc.c
index a722bac6185a..8fc52c6749e1 100644
--- a/sys/kern/kern_proc.c
+++ b/sys/kern/kern_proc.c
@@ -2891,6 +2891,8 @@ sysctl_kern_proc_kstack(SYSCTL_HANDLER_ARGS)
execve_unblock(ctd, p);
_PRELE(p);
PROC_UNLOCK(p);
+ stack_destroy(st);
+ free(kkstp, M_TEMP);
return (error);
}
do {