В ядре Linux устранена следующая уязвимость:
net/smc: не разыменовывать неустановленный буфер отправки на пути удаления SMC-D.
smc_close_stream_wait() вызывает smc_tx_prepared_sends() изнутри своего
условие sk_wait_event(), а sk_wait_event() оценивает это условие.
один раз с отпущенным фиксатором розетки. smcd_buf_detach() очищает
conn->sndbuf_desc из smc_conn_kill() под lock_sock(), поэтому группа ссылок
завершение, пока сокет ожидает, приводит к разыменовыванию помощника
NULL, ошибка закрытия(). SIOCOUTQ читает поле вручную и
smc_close_cancel_work() снимает блокировку между двумя вызовами cancel_*_sync().
Попробуйте указатель один раз в помощнике, не сообщайте ничего подготовленного, пока он находится
unset и таким же образом связал ioctl. Разыменования тасклета получения
поле непосредственно в smc_cdc_msg_recv_action(), а не через этот помощник;
1/2 — это то, что не дает ему работать так поздно.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late.