Fedora Account System
Red Hat Associate
Red Hat Customer
We can see that undef "#ifdef SA_RESTART", sa.sa_flags has its SA_RESTART bit set without being initialized previously. The concern Brain raised is that, depending on the contents of the stack, sa.sa_flags may also have its SA_RESTORER bit set. In addition, the sa.sa_restorer field would be uninitialized, meaning it would be set to whatever is on the stack. This field is a function pointer that is used as a signal trampoline used on some architectures, meaning that it is used to return from the signal handler back to the code that was executing at the time the signal was delivered. I am not very familiar with these signal details, so I asked Adhemerval Zanella Netto, a glibc maintainer, if he could take a look at the report to help us better understand the security impact. He mentioned that most new generic Linux ports are not affected Ability to reproduce this consistently with custom setsockopt() implementation by exiting or using CTRL + C in the telnet session, which triggered SIGCHLD.