В ядре Linux устранена следующая уязвимость:
Platform/x86/amd/pmc: исправлены утечки LPS0 и debugfs при сбое инициализации STB.
amd_pmc_probe() регистрирует обработчик s2idle LPS0 с помощью
acpi_register_lps0_dev() и перед этим создает каталог debugfs драйвера.
вызов amd_stb_s2d_init(), который является последним шагом проверки, на котором может произойти сбой. При сбое amd_stb_s2d_init() (например, область телеметрии S2D не может
быть отображено в долго работающей системе, или SMU отклонит настройку S2D)
путь ошибки вызывает только pci_dev_put() и возвращает результат. Это оставляет
amd_pmc_s2idle_dev_ops в глобальном списке lps0_s2idle_devops_head и утечках
каталог debugfs, а ресурсы, управляемые devm, поддерживающие обработчик
снесены.
Перезагрузка модуля затем перемещает поврежденный список в
acpi_register_lps0_dev() и выполняет:
list_add повреждение. next->prev должно быть prev, но было NULL. ОШИБКА ядра в lib/list_debug.c:29!
acpi_register_lps0_dev+0x44/0x80
amd_pmc_probe+0x224/0x380 [amd_pmc]
Platform_probe+0x67/0x90
Даже без перезагрузки устаревшая регистрация означает следующий s2idle.
вызовы перехода в состояние отключенного драйвера. Отверните каталог debugfs и регистрацию LPS0 на
Путь ошибки amd_stb_s2d_init(). acpi_unregister_lps0_dev() можно безопасно вызывать
здесь безусловно: охраняется на тех же условиях, что и
acpi_register_lps0_dev(), что уже есть в amd_pmc_remove()
полагается.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails amd_pmc_probe() registers the LPS0 s2idle handler with acpi_register_lps0_dev() and creates the driver's debugfs directory before calling amd_stb_s2d_init(), which is the last step in probe that can fail. When amd_stb_s2d_init() fails (for example the S2D telemetry region cannot be ioremapped on a long-running system, or the SMU rejects the S2D setup) the error path only calls pci_dev_put() and returns. This leaves amd_pmc_s2idle_dev_ops on the global lps0_s2idle_devops_head list and leaks the debugfs directory, while the devm-managed resources backing the handler are torn down. Reloading the module then walks the corrupted list in acpi_register_lps0_dev() and hits: list_add corruption. next->prev should be prev, but was NULL. kernel BUG at lib/list_debug.c:29! acpi_register_lps0_dev+0x44/0x80 amd_pmc_probe+0x224/0x380 [amd_pmc] platform_probe+0x67/0x90 Even without a reload, the stale registration means the next s2idle transition calls into torn-down driver state. Unwind the debugfs directory and the LPS0 registration on the amd_stb_s2d_init() error path. acpi_unregister_lps0_dev() is safe to call unconditionally here: it is guarded on the same conditions as acpi_register_lps0_dev(), which is exactly what amd_pmc_remove() already relies on.
Характеристики атаки
Последствия
Строка CVSS v3.1