| From d19cdc167e696714509e87d3f7ae765b6e164589 Mon Sep 17 00:00:00 2001 |
| From: Bradley Morgan <include@grrlz.net> |
| Date: Mon, 22 Jun 2026 20:25:08 +0000 |
| Subject: signal: avoid shared siginfo namespace rewrites |
| |
| From: Bradley Morgan <include@grrlz.net> |
| |
| commit d19cdc167e696714509e87d3f7ae765b6e164589 upstream. |
| |
| send_signal_locked() rewrites sender ids for the target namespace. Group |
| sends reuse the same siginfo, so one recipient can affect the next. |
| |
| Copy the siginfo before changing it. |
| |
| Link: https://lore.kernel.org/86a8857d58d43ee26a8b365b837fd24830343494.1782159692.git.include@grrlz.net |
| Fixes: 7a0cf094944e ("signal: Correct namespace fixups of si_pid and si_uid") |
| Signed-off-by: Bradley Morgan <include@grrlz.net> |
| Acked-by: Oleg Nesterov <oleg@redhat.com> |
| Cc: "Eric W. Biederman" <ebiederm@xmission.com> |
| Cc: Adrian Huang <adrianhuang0701@gmail.com> |
| Cc: Aleksandr Nogikh <nogikh@google.com> |
| Cc: Christian Brauner <brauner@kernel.org> |
| Cc: Marco Elver <elver@google.com> |
| Cc: "Masami Hiramatsu (Google)" <mhiramat@kernel.org> |
| Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com> |
| Cc: Peter Zijlstra <peterz@infradead.org> |
| Cc: Steven Rostedt <rostedt@goodmis.org> |
| Cc: <stable@vger.kernel.org> |
| Signed-off-by: Andrew Morton <akpm@linux-foundation.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| kernel/signal.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| --- a/kernel/signal.c |
| +++ b/kernel/signal.c |
| @@ -1209,6 +1209,7 @@ static inline bool has_si_pid_and_uid(st |
| static int send_signal(int sig, struct kernel_siginfo *info, struct task_struct *t, |
| enum pid_type type) |
| { |
| + struct kernel_siginfo rewritten; |
| /* Should SIGKILL or SIGSTOP be received by a pid namespace init? */ |
| bool force = false; |
| |
| @@ -1222,6 +1223,9 @@ static int send_signal(int sig, struct k |
| /* SIGKILL and SIGSTOP is special or has ids */ |
| struct user_namespace *t_user_ns; |
| |
| + rewritten = *info; |
| + info = &rewritten; |
| + |
| rcu_read_lock(); |
| t_user_ns = task_cred_xxx(t, user_ns); |
| if (current_user_ns() != t_user_ns) { |