В ядре Linux устранена следующая уязвимость:
sched_ext: не BUG_ON уничтоженного DSQ вprocess_deferred_reenq_users
scx_bpf_dsq_reenq() ставит в очередь отложенный повторный запрос (dru), который запускается из
run_deferred(), а не ops.dispatch(). Если DSQ уничтожен до того, как дру
запускается, процесс_deferred_reenq_users() видит dsq->id == SCX_DSQ_INVALID и
попадает в BUG_ON. Destroy_dsq() не сбрасывает ожидающие Drus, поэтому просто пропустите.
tj: Прочитайте dsq->id один раз с помощью READ_ONCE(). Чтение его отдельно в INVALID
проверьте, и BUG_ON оставит окно, в котором Destroy_dsq() может
сделать недействительным идентификатор между двумя чтениями и по-прежнему вызывать BUG_ON.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users scx_bpf_dsq_reenq() queues a deferred reenq (dru) that runs from run_deferred(), not ops.dispatch(). If the DSQ is destroyed before the dru runs, process_deferred_reenq_users() sees dsq->id == SCX_DSQ_INVALID and hits the BUG_ON. destroy_dsq() doesn't flush pending drus, so just skip. tj: Read dsq->id once with READ_ONCE(). Reading it separately in the INVALID check and the BUG_ON would leave a window where destroy_dsq() can invalidate the id between the two reads and still trigger the BUG_ON.