NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

bin/60841: kdc(8) sends pids to signals instead of signals to pids



>Number:         60841
>Category:       bin
>Synopsis:       kdc(8) sends pids to signals instead of signals to pids
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    bin-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Sat Oct 03 04:35:00 +0000 2026
>Originator:     Taylor R Campbell
>Release:        current, 11, 10, ...
>Organization:
.cnI ,noitallangiS CDKteN ehT
>Environment:
>Description:

	When the KDC process supervisor exits, after notifying children
	gracefully, if the children don't exit promptly enough, then as
	a fallback it sends SIGTERM and then SIGKILL to the child pids.

	Or it tries to, anyway.

	Actually, it sends the child pids to SIGTERM and then SIGKILL,
	that is, passes the pid as the signal argument and the signal
	as the pid argument to kill(2) by mistake:

   1015     for (i=0; i < max_kids; i++)
   1016 	if (pids[i] > 0)
   1017 	    kill(sig, pids[i]);

	https://nxr.netbsd.org/xref/src/crypto/external/bsd/heimdal/dist/kdc/connect.c?r=1.5#1015

	Which is to say, it might send some random signal to some
	random process which happens to have pid 9 or 15 if you're
	unlucky.

	Fortunately it only does this if the primary mechanism of
	waking the child processes fails.

>How-To-Repeat:

	code inspection

>Fix:

	pull upstream commit b22f33250a98efcda3a07fdc36bc2fd386230857




Home | Main Index | Thread Index | Old Index