]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
futex: Require sys_futex_requeue() to have identical flags
authorPeter Zijlstra <peterz@infradead.org>
Thu, 26 Mar 2026 12:35:53 +0000 (13:35 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 2 Apr 2026 11:25:56 +0000 (13:25 +0200)
commite2f78c7ec1655fedd945366151ba54fcb9580508
tree707ebc9b35a64bcc3fd7685c8e4a4460aa3a6540
parent4d95d65fd099cdba0c6b38008993786810b359c4
futex: Require sys_futex_requeue() to have identical flags

[ Upstream commit 19f94b39058681dec64a10ebeb6f23fe7fc3f77a ]

Nicholas reported that his LLM found it was possible to create a UaF
when sys_futex_requeue() is used with different flags. The initial
motivation for allowing different flags was the variable sized futex,
but since that hasn't been merged (yet), simply mandate the flags are
identical, as is the case for the old style sys_futex() requeue
operations.

Fixes: 0f4b5f972216 ("futex: Add sys_futex_requeue()")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
kernel/futex/syscalls.c