Fix CVE-2022-3565 - #10
Merged
gvrose8192 merged 1 commit intoNov 19, 2024
Merged
gvrose8192 merged 1 commit into
gvrose8192 merged 1 commit into
Conversation
jira VULN-168 cve CVE-2022-3565 commit-author Duoming Zhou <duoming@zju.edu.cn> commit 2568a7e The l1oip_cleanup() traverses the l1oip_ilist and calls release_card() to cleanup module and stack. However, release_card() calls del_timer() to delete the timers such as keep_tl and timeout_tl. If the timer handler is running, the del_timer() will not stop it and result in UAF bugs. One of the processes is shown below: (cleanup routine) | (timer handler) release_card() | l1oip_timeout() ... | del_timer() | ... ... | kfree(hc) //FREE | | hc->timeout_on = 0 //USE Fix by calling del_timer_sync() in release_card(), which makes sure the timer handlers have finished before the resources, such as l1oip and so on, have been deallocated. What's more, the hc->workq and hc->socket_thread can kick those timers right back in. We add a bool flag to show if card is released. Then, check this flag in hc->workq and hc->socket_thread. Fixes: 3712b42 ("Add layer1 over IP support") Signed-off-by: Duoming Zhou <duoming@zju.edu.cn> Reviewed-by: Leon Romanovsky <leonro@nvidia.com> Signed-off-by: David S. Miller <davem@davemloft.net> (cherry picked from commit 2568a7e) Signed-off-by: Greg Rose <g.v.rose@ciq.com>
PlaidCat
approved these changes
Nov 19, 2024
bmastbergen
approved these changes
Nov 19, 2024
gvrose8192
deleted the
gvrose_fips-legacy-8-compliant/4.18.0-425.13.1
branch
November 19, 2024 22:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Commit message
Builds:
Boots and runs:
Before and after kernel selftests show no changes:
kernel-selftest-before.log
kernel-selftest-after.log
The nature of the change is such that we do not have the system HW and setup to test the change and get code coverage. We'll have to depend on the patch applying cleanly and the expertise of the folks who created it.