В ядре Linux устранена следующая уязвимость:
PCI: plda: исправлены утечки домена IRQ в путях ошибок plda_init_interrupts().
plda_init_interrupts() инициализирует домены IRQ и создает сопоставление IRQ, но
не разматывает их, если на более позднем этапе произошел сбой. Если Platform_get_irq() или irq_create_mapping() завершаются неудачно
в plda_init_interrupts() домены никогда не деинициализируются. Если
irq_create_mapping() завершается с ошибкой, порт->intx_irq остается инициализированным.
Следовательно, удалите домены IRQ в пути ошибки, вызвав
plda_pcie_irq_domain_deinit(). Поскольку plda_pcie_irq_domain_deinit() теперь удаляет intx_irq и
msi_irq сопоставляет себя перед удалением их доменов, msi_irq
путь ошибки сопоставления может идти непосредственно к err_irq_domain_deinit вместо
сначала удалите порт->intx_irq отдельно. Эта проблема была обнаружена при автоматической проверке sashiko-bot.
[мани: журнал фиксации]
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind them when later step fails. If platform_get_irq() or either irq_create_mapping() fails in plda_init_interrupts(), the domains are never deinitialized. If irq_create_mapping() fails, port->intx_irq stays initialized. Hence, remove the IRQ domains in the error path by calling plda_pcie_irq_domain_deinit(). Since plda_pcie_irq_domain_deinit() now disposes of the intx_irq and msi_irq mappings itself before removing their domains, the msi_irq mapping failure path can go directly to err_irq_domain_deinit instead of disposing of port->intx_irq separately first. This issue was found by automated review of sashiko-bot [mani: commit log]