В ядре Linux устранена следующая уязвимость:
sunrpc: исправлено использование после освобождения в __rpc_clnt_handle_event и __rpc_clnt_remove_pipedir
Обычное создание клиента происходит через rpc_setup_pipedir(), который записывает
clnt->pipefs_sb, но путь монтирования в __rpc_clnt_handle_event()
вызывает rpc_setup_pipedir_sb() напрямую и никогда не обновляет это поле. Путь размонтирования также удаляет каталог без очистки.
clnt->pipefs_sb. После позднего монтирования Pipefs или любого перемонтирования, rpc_clnt_remove_pipedir()
сравнивает текущий суперблок с устаревшим указателем Pipefs_sb и
пропускает очистку, оставляя dentries Pipefs, чьи личные данные inode все еще
указывает на освобожденный rpc_clnt, что приводит к потенциальному использованию после освобождения во время
последующие вызовы rpc_info_open() или rpc_show_info().
Исправьте это, правильно обновив clnt->pipefs_sb после событий монтирования и очистка его во время размонтирования или путей сбоя.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir Normal client creation goes through rpc_setup_pipedir(), which records clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event() calls rpc_setup_pipedir_sb() directly and never refreshes that field. The umount path also removes the directory without clearing clnt->pipefs_sb. After a late pipefs mount or any remount, rpc_clnt_remove_pipedir() compares the current superblock against a stale pipefs_sb pointer and skips cleanup, leaving pipefs dentries whose inode private data still points at a freed rpc_clnt, leading to a potential use-after-free during subsequent rpc_info_open() or rpc_show_info() calls. Fix this by properly updating clnt->pipefs_sb upon mount events and clearing it during unmount or failure paths.