Repository navigation
Conversation
RegionValidate() copies *badreg into ri[0].reg, so ri[0].reg.data aliases badreg->data. A later RECTALLOC_BAIL() can realloc() that block and move it, updating ri[0].reg.data but not badreg->data. On the bail path, freeing ri[0].reg.data and then calling RegionBreak(badreg) frees badreg->data a second time, which by then is a stale pointer into memory already freed or reallocated to something else. Signed-off-by: Jeremy Huddleston Sequoia <jeremyhu@apple.com> Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2281> (cherry picked from commit 4ef1b4c) (cherry picked from commit bb02769445b1a516f33b4855977cc227f0542cb7) (cherry picked from commit bc0760d)
…or path RegionValidate() copies *badreg into ri[0].reg, so ri[0].reg.data aliases badreg->data. A later RECTALLOC_BAIL() can realloc() that block and move it, updating ri[0].reg.data but not badreg->data. On the bail path, freeing ri[0].reg.data and then calling RegionBreak(badreg) frees badreg->data a second time, which by then is a stale pointer into memory already freed or reallocated to something else. Signed-off-by: Jeremy Huddleston Sequoia <jeremyhu@apple.com> Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2281> (cherry picked from commit 4ef1b4c) (cherry picked from commit bb02769445b1a516f33b4855977cc227f0542cb7) (cherry picked from commit bc0760d) PR: #3779
Review: passed — backport candidate (memory safety)Genuine use-after-free / double-free on the error path. I verified the mechanism against Why it looks redundant, and why it is notThe patch adds The reason is static inline void xfreeData(RegionPtr reg) {
if (reg && reg->data && reg->data->size && /* <-- dereferences data */
reg->data != &RegionBrokenData &&
reg->data != &RegionEmptyData)
free(reg->data);
}
It matches the function's own established idiomThe same function already does exactly this a few lines earlier, on the xfreeData(badreg);
badreg->data = (RegDataPtr) NULL;So the patch is consistent with how this function already handles "data freed, pointer Aliasing premiseThe commit message states that Backport: yes, all release linesBackport-worthy — use-after-free and double-free, reachable through region validation. |
…or path RegionValidate() copies *badreg into ri[0].reg, so ri[0].reg.data aliases badreg->data. A later RECTALLOC_BAIL() can realloc() that block and move it, updating ri[0].reg.data but not badreg->data. On the bail path, freeing ri[0].reg.data and then calling RegionBreak(badreg) frees badreg->data a second time, which by then is a stale pointer into memory already freed or reallocated to something else. Signed-off-by: Jeremy Huddleston Sequoia <jeremyhu@apple.com> Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2281> (cherry picked from commit 4ef1b4c) (cherry picked from commit bb02769445b1a516f33b4855977cc227f0542cb7) (cherry picked from commit bc0760d) PR: #3779
…or path RegionValidate() copies *badreg into ri[0].reg, so ri[0].reg.data aliases badreg->data. A later RECTALLOC_BAIL() can realloc() that block and move it, updating ri[0].reg.data but not badreg->data. On the bail path, freeing ri[0].reg.data and then calling RegionBreak(badreg) frees badreg->data a second time, which by then is a stale pointer into memory already freed or reallocated to something else. Signed-off-by: Jeremy Huddleston Sequoia <jeremyhu@apple.com> Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2281> (cherry picked from commit 4ef1b4c) (cherry picked from commit bb02769445b1a516f33b4855977cc227f0542cb7) (cherry picked from commit bc0760d) PR: #3779
Backport-Übersicht — Merge-Status liveDie Referenzen stehen als Task-Liste, damit GitHub jede beim Rendern zu einem
Auflösung: |
RegionValidate() copies *badreg into ri[0].reg, so ri[0].reg.data aliases badreg->data. A later
RECTALLOC_BAIL() can realloc() that block and move it, updating ri[0].reg.data but not badreg->data. On
the bail path, freeing ri[0].reg.data and then calling RegionBreak(badreg) frees badreg->data a second
time, which by then is a stale pointer into memory already freed or reallocated to something else.
Signed-off-by: Jeremy Huddleston Sequoia jeremyhu@apple.com
Part-of: https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2281
(cherry picked from commit 4ef1b4c)
(cherry picked from commit bb02769445b1a516f33b4855977cc227f0542cb7)
(cherry picked from commit bc0760d)
Release merges are manual, by the maintainer.