[SRU groovy 7/9] futex: Use pi_state_update_owner() in put_pi_state()

Thadeu Lima de Souza Cascardo cascardo at canonical.com
Tue Mar 9 17:03:30 UTC 2021


From: Thomas Gleixner <tglx at linutronix.de>

No point in open coding it. This way it gains the extra sanity checks.

Signed-off-by: Thomas Gleixner <tglx at linutronix.de>
Acked-by: Peter Zijlstra (Intel) <peterz at infradead.org>
Cc: stable at vger.kernel.org
(cherry picked from commit 6ccc84f917d33312eb2846bd7b567639f585ad6d)
CVE-2021-3347
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo at canonical.com>
---
 kernel/futex.c | 8 +-------
 1 file changed, 1 insertion(+), 7 deletions(-)

diff --git a/kernel/futex.c b/kernel/futex.c
index 42af43749238..9ba115fcd8c5 100644
--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -827,16 +827,10 @@ static void put_pi_state(struct futex_pi_state *pi_state)
 	 * and has cleaned up the pi_state already
 	 */
 	if (pi_state->owner) {
-		struct task_struct *owner;
 		unsigned long flags;
 
 		raw_spin_lock_irqsave(&pi_state->pi_mutex.wait_lock, flags);
-		owner = pi_state->owner;
-		if (owner) {
-			raw_spin_lock(&owner->pi_lock);
-			list_del_init(&pi_state->list);
-			raw_spin_unlock(&owner->pi_lock);
-		}
+		pi_state_update_owner(pi_state, NULL);
 		rt_mutex_proxy_unlock(&pi_state->pi_mutex);
 		raw_spin_unlock_irqrestore(&pi_state->pi_mutex.wait_lock, flags);
 	}
-- 
2.27.0




More information about the kernel-team mailing list