В ядре Linux устранена следующая уязвимость:
cifs: очистить tcon после cifsFileInfo_put() в cifs_file_set_size()
Когда ветвь else функции cifs_file_set_size() находит доступный для записи дескриптор файла
через find_writable_file() он заимствует tcon и сервер из дескриптора
tlink пытается выполнить RPC set_file_size() на основе дескриптора, а затем отпускает
дескриптор с помощью cifsFileInfo_put(). Если set_file_size() завершается неудачно, выполнение переходит к методу, основанному на пути.
резервный вариант, который повторно использует заимствованный tcon и сервер под
"if (tcon == NULL)" Guard. Поскольку в этот момент tcon не равен NULL,
охрана пропускается.
Если cifsFileInfo_put() удалил последнюю ссылку на
tlink, который уже был удален из дерева tlink (TCON_LINK_IN_TREE
очищается, как это происходит при переподключении или разрыве сеанса),
cifs_put_tlink() освободит tcon; последующий set_path_size()
вызов тогда является использованием после освобождения. Установка tcon = NULL после cifsFileInfo_put() вызывает существующую защиту
взять путь cifs_sb_tlink(), который получает новую ссылку для
операция на основе пути или завершается с ошибкой, если сеанс завершен.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() When the else branch of cifs_file_set_size() finds a writable file handle via find_writable_file(), it borrows tcon and server from the handle's tlink, attempts the handle-based set_file_size() RPC, and then releases the handle with cifsFileInfo_put(). If set_file_size() fails, execution falls through to the path-based fallback, which reuses the borrowed tcon and server under the "if (tcon == NULL)" guard. Since tcon is not NULL at that point, the guard is skipped. If cifsFileInfo_put() dropped the last reference on a tlink that was already removed from the tlink tree (TCON_LINK_IN_TREE cleared, as happens during reconnection or session teardown), cifs_put_tlink() will have freed tcon; the subsequent set_path_size() call is then a use-after-free. Setting tcon = NULL after cifsFileInfo_put() causes the existing guard to take the cifs_sb_tlink() path, which acquires a fresh reference for the path-based operation or fails cleanly if the session is gone.
Характеристики атаки
Последствия
Строка CVSS v3.1