В ядре Linux устранена следующая уязвимость:
ata: pata_sl82c105: исправить версию моста use-after-free
pci_get_slot() возвращает указанное PCI-устройство. Зафиксировать 44c10138fd4b
(«PCI: изменить все драйверы на использование pci_device->revision») заменил
чтение пространства конфигурации с прямым доступом к кэшированному полю ревизии,
но оставил этот доступ после pci_dev_put(). Таким образом, мост может быть освобожден
до того, как его редакция будет прочитана.
Прочтите редакцию, прежде чем удалять ссылку.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: ata: pata_sl82c105: fix bridge revision use-after-free pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b ("PCI: Change all drivers to use pci_device->revision") replaced a configuration-space read with direct access to the cached revision field, but left that access after pci_dev_put(). The bridge may therefore be freed before its revision is read. Read the revision before dropping the reference.
Характеристики атаки
Последствия
Строка CVSS v3.1
Уязвимые продукты 8
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
5.10.265
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
5.15.216
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
6.1.183
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
6.6.152
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
6.12.104
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
6.18.45
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
7.1.9
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
2.6.23
|
7.2
|