elf: Fix data race in _dl_name_match_p [BZ #21349]
commit395be7c2184645320c955b0ba214af9fa1ea9675
authorManinder Singh <maninder1.s@samsung.com>
Wed, 10 Jan 2018 15:17:30 +0000 (10 15:17 +0000)
committerSzabolcs Nagy <szabolcs.nagy@arm.com>
Tue, 6 Apr 2021 13:44:09 +0000 (6 14:44 +0100)
treedd3d5623c2fbf20dcae590efcfdfa58c6f48dc34
parent69499bb6eeb4f5d1b3502758208301d21042a783
elf: Fix data race in _dl_name_match_p [BZ #21349]

dlopen updates libname_list by writing to lastp->next, but concurrent
reads in _dl_name_match_p were not synchronized when it was called
without holding GL(dl_load_lock), which can happen during lazy symbol
resolution.

This patch fixes the race between _dl_name_match_p reading lastp->next
and add_name_to_object writing to it. This could cause segfault on
targets with weak memory order when lastp->next->name is read, which
was observed on an arm system. Fixes bug 21349.

(Code is from Maninder Singh, comments and description is from Szabolcs
Nagy.)

Co-authored-by: Vaneet Narang <v.narang@samsung.com>
Co-authored-by: Szabolcs Nagy <szabolcs.nagy@arm.com>
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
elf/dl-load.c
elf/dl-misc.c