git: 5db05b5dedf3 - stable/15 - kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 15:56:19 UTC
The branch stable/15 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=5db05b5dedf38cc9e31f89a9f4df9abb5cb1b539

commit 5db05b5dedf38cc9e31f89a9f4df9abb5cb1b539
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-28 13:42:54 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 15:56:01 +0000

    kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()
    
    Here, fdp points to the new fdtable, copied from that of the parent
    process.  There is a window after the fdtable is copied, and before
    kqueue_fork_copy_knote() runs, where a different thread in the parent
    could have grown the parent's fdtable and registered a knote with ident
    larger than the size of the child's fdtable.  This race can lead to an
    out-of-bounds read.
    
    Add a bounds check for this case; skip the knote if it is referencing a
    non-existent file.
    
    Approved by:    so
    Security:       FreeBSD-SA-26:65.kqueue
    Security:       CVE-2026-58100
    Reviewed by:    kib
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59916
---
 sys/kern/kern_event.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sys/kern/kern_event.c b/sys/kern/kern_event.c
index 32e2e6e69d7e..5bfa6f8a800e 100644
--- a/sys/kern/kern_event.c
+++ b/sys/kern/kern_event.c
@@ -3108,7 +3108,8 @@ kqueue_fork_copy_knote(struct kqueue *kq, struct kqueue *kq1, struct knote *kn,
 	}
 	fop = kn->kn_fop;
 	if (fop->f_copy == NULL || (fop->f_isfd &&
-	    fdp->fd_files->fdt_ofiles[kn->kn_kevent.ident].fde_file == NULL))
+	    ((unsigned int)fdp->fd_files->fdt_nfiles <= kn->kn_kevent.ident ||
+	    fdp->fd_files->fdt_ofiles[kn->kn_kevent.ident].fde_file == NULL)))
 		return;
 	error = kqueue_expand(kq1, fop, kn->kn_kevent.ident, M_WAITOK);
 	if (error != 0)