В ядре Linux устранена следующая уязвимость:
ipmi: удалить все файлы sysfs при ошибке регистрации.
ipmi_add_smi() создает файлы nr_users и nr_msgs перед попыткой
создайте файл Maintenance_mode. Если это последнее создание не удалось, ошибка
path удаляет только nr_users перед удалением окончательной ссылки на
интерфейс.
Удалите также nr_msgs, чтобы атрибут sysfs не был встроен в освобожденный файл.
интерфейс остается зарегистрированным.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes only nr_users before dropping the final reference to the interface. Remove nr_msgs as well so no sysfs attribute embedded in the freed interface remains registered.
Характеристики атаки
Последствия
Строка CVSS v3.1