В ядре Linux устранена следующая уязвимость:
медиа: staging/ipu7: исправить асинхронный уведомитель UAF на пути ошибки зонда
isys_register_devices() регистрирует асинхронный уведомитель V4L2 через
isys_notifier_init(). Если последующий этап проверки, такой как
isys_fw_log_init() завершается с ошибкой, isys_probe() переходит к метке out_cleanup
который вызывает только isys_unregister_devices(). Этот помощник срывает
видеоустройства, субустройства, устройства V4L2 и мультимедийные устройства, но никогда
отменяет регистрацию или очищает асинхронный уведомитель.
В результате уведомитель остается привязанным к глобальному notifier_list, пока
включающая структура ipu7_isys освобождается devres, что приводит к списку
повреждение и использование после освобождения при следующем просмотре списка. Путь удаления уже делает правильные вещи, вызывая
isys_notifier_cleanup() перед isys_unregister_devices(). Отразите это на
путь ошибки зонда, чтобы уведомитель был отменен и очищен
прежде чем устройство будет снесено.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: media: staging/ipu7: fix async notifier UAF on probe error path isys_register_devices() registers the V4L2 async notifier via isys_notifier_init(). If a subsequent probe step such as isys_fw_log_init() fails, isys_probe() jumps to the out_cleanup label which only calls isys_unregister_devices(). That helper tears down the video devices, subdevices, V4L2 device and media device, but never unregisters or cleans up the async notifier. As a result the notifier stays chained in the global notifier_list while the enclosing struct ipu7_isys is freed by devres, leading to list corruption and a use-after-free the next time the list is walked. The remove path already does the right thing by calling isys_notifier_cleanup() before isys_unregister_devices(). Mirror that on the probe error path so the notifier is unregistered and cleaned up before the device is torn down.
Характеристики атаки
Последствия
Строка CVSS v3.1