security fix: check that cancel/rsyscall signal was sent by the process itself
This commit is contained in:
parent
11dbbe9fba
commit
52213f7341
1 changed files with 3 additions and 0 deletions
|
|
@ -45,6 +45,7 @@ static void docancel(struct pthread *self)
|
||||||
static void cancel_handler(int sig, siginfo_t *si, void *ctx)
|
static void cancel_handler(int sig, siginfo_t *si, void *ctx)
|
||||||
{
|
{
|
||||||
struct pthread *self = __pthread_self();
|
struct pthread *self = __pthread_self();
|
||||||
|
if (si->si_code > 0 || si->si_pid != self->pid) return;
|
||||||
self->cancel = 1;
|
self->cancel = 1;
|
||||||
if (self->canceldisable || (!self->cancelasync && !self->cancelpoint))
|
if (self->canceldisable || (!self->cancelasync && !self->cancelpoint))
|
||||||
return;
|
return;
|
||||||
|
|
@ -75,6 +76,8 @@ static struct {
|
||||||
|
|
||||||
static void rsyscall_handler(int sig, siginfo_t *si, void *ctx)
|
static void rsyscall_handler(int sig, siginfo_t *si, void *ctx)
|
||||||
{
|
{
|
||||||
|
if (si->si_code > 0 || si->si_pid != __pthread_self()->pid) return;
|
||||||
|
|
||||||
if (rs.cnt == libc.threads_minus_1) return;
|
if (rs.cnt == libc.threads_minus_1) return;
|
||||||
|
|
||||||
if (syscall6(rs.nr, rs.arg[0], rs.arg[1], rs.arg[2],
|
if (syscall6(rs.nr, rs.arg[0], rs.arg[1], rs.arg[2],
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue