NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
bin/60841: kdc(8) sends pids to signals instead of signals to pids
>Number: 60841
>Category: bin
>Synopsis: kdc(8) sends pids to signals instead of signals to pids
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: bin-bug-people
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Sat Oct 03 04:35:00 +0000 2026
>Originator: Taylor R Campbell
>Release: current, 11, 10, ...
>Organization:
.cnI ,noitallangiS CDKteN ehT
>Environment:
>Description:
When the KDC process supervisor exits, after notifying children
gracefully, if the children don't exit promptly enough, then as
a fallback it sends SIGTERM and then SIGKILL to the child pids.
Or it tries to, anyway.
Actually, it sends the child pids to SIGTERM and then SIGKILL,
that is, passes the pid as the signal argument and the signal
as the pid argument to kill(2) by mistake:
1015 for (i=0; i < max_kids; i++)
1016 if (pids[i] > 0)
1017 kill(sig, pids[i]);
https://nxr.netbsd.org/xref/src/crypto/external/bsd/heimdal/dist/kdc/connect.c?r=1.5#1015
Which is to say, it might send some random signal to some
random process which happens to have pid 9 or 15 if you're
unlucky.
Fortunately it only does this if the primary mechanism of
waking the child processes fails.
>How-To-Repeat:
code inspection
>Fix:
pull upstream commit b22f33250a98efcda3a07fdc36bc2fd386230857
Home |
Main Index |
Thread Index |
Old Index