Skip to content

[release/10.0] Fix TOCTOU race in AppDomain::LoadAssembly fast-path#125424

Open
github-actions[bot] wants to merge 1 commit intorelease/10.0from
backport/pr-125408-to-release/10.0
Open

[release/10.0] Fix TOCTOU race in AppDomain::LoadAssembly fast-path#125424
github-actions[bot] wants to merge 1 commit intorelease/10.0from
backport/pr-125408-to-release/10.0

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Mar 11, 2026

Backport of #125408 to release/10.0

/cc @AaronRobinsonMSFT

Customer Impact

  • Customer reported
  • Found internally

[Select one or both of the boxes. Describe how this issue impacts customers, citing the expected and actual behaviors and scope of the issue. If customer-reported, provide the issue number.]

Regression

  • Yes
  • No

[If yes, specify when the regression was introduced. Provide the PR or commit if known.]

Testing

[How was the fix verified? How was the issue missed previously? What tests were added?]

Risk

[High/Medium/Low. Justify the indication by mentioning how risks were measured and addressed.]

IMPORTANT: If this backport is for a servicing release, please verify that:

  • For .NET 8 and .NET 9: The PR target branch is release/X.0-staging, not release/X.0.
  • For .NET 10+: The PR target branch is release/X.0 (no -staging suffix).

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

PR #120515 deferred Assembly creation (lazy init), making
FileLoadLock::m_pAssembly mutable. The fast-path in LoadAssembly
cached pAssembly before checking GetLoadLevel(), so a thread could
read nullptr, get preempted while another thread completed the load,
then pass the level check and dereference the stale nullptr.

Re-read pAssembly from the FileLoadLock inside the fast-path block
after the level check passes, ensuring we use the pointer that
corresponds to the observed load level.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dotnet-policy-service
Copy link
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant