В ядре Linux устранена следующая уязвимость:
wifi: rtw89: исправлен неверный тип pci_get_drvdata в обработчиках AER.
rtw89 сохраняет указатель ieee80211_hw через pci_set_drvdata() в зонде
время, но io_error_detected() и io_resume() извлекают его как
указатель net_device. Это приводит к тому, что netif_device_detach/attach
работать со структурой ieee80211_hw, неправильно читая и записывая
смещения. Соседний io_slot_reset() уже делает это правильно.
Вместо этого используйте ieee80211_stop_queues/wake_queues в соответствии с
каждый второй путь остановки/запуска очереди в драйвере. Протестировано на RTL8852CE путем вызова обработчиков из тестового модуля.
до и после исправления.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers rtw89 stores an ieee80211_hw pointer via pci_set_drvdata() at probe time, but io_error_detected() and io_resume() retrieve it as a net_device pointer. This causes netif_device_detach/attach to operate on an ieee80211_hw struct, reading and writing at wrong offsets. The adjacent io_slot_reset() already does it correctly. Use ieee80211_stop_queues/wake_queues instead, consistent with every other queue stop/start path in the driver. Tested on RTL8852CE by calling the handlers from a test module before and after the fix.
Характеристики атаки
Последствия
Строка CVSS v3.1