git: 2b66c28a0383 - releng/15.1 - kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 16:00:04 UTC
The branch releng/15.1 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=2b66c28a03832c2e2e4f098f8e5f38dd1c46e933

commit 2b66c28a03832c2e2e4f098f8e5f38dd1c46e933
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-28 13:42:54 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 01:01:48 +0000

    kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()
    
    Here, fdp points to the new fdtable, copied from that of the parent
    process.  There is a window after the fdtable is copied, and before
    kqueue_fork_copy_knote() runs, where a different thread in the parent
    could have grown the parent's fdtable and registered a knote with ident
    larger than the size of the child's fdtable.  This race can lead to an
    out-of-bounds read.
    
    Add a bounds check for this case; skip the knote if it is referencing a
    non-existent file.
    
    Approved by:    so
    Security:       FreeBSD-SA-26:65.kqueue
    Security:       CVE-2026-58100
    Reviewed by:    kib
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59916
---
 sys/kern/kern_event.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sys/kern/kern_event.c b/sys/kern/kern_event.c
index ec9036bd30de..11348a443737 100644
--- a/sys/kern/kern_event.c
+++ b/sys/kern/kern_event.c
@@ -3097,7 +3097,8 @@ kqueue_fork_copy_knote(struct kqueue *kq, struct kqueue *kq1, struct knote *kn,
 	}
 	fop = kn->kn_fop;
 	if (fop->f_copy == NULL || (fop->f_isfd &&
-	    fdp->fd_files->fdt_ofiles[kn->kn_kevent.ident].fde_file == NULL))
+	    ((unsigned int)fdp->fd_files->fdt_nfiles <= kn->kn_kevent.ident ||
+	    fdp->fd_files->fdt_ofiles[kn->kn_kevent.ident].fde_file == NULL)))
 		return;
 	error = kqueue_expand(kq1, fop, kn->kn_kevent.ident, M_WAITOK);
 	if (error != 0)