В ядре Linux устранена следующая уязвимость:
nfsd: исправление UAF при отмене и завершении асинхронного копирования. Асинхронная копия может быть освобождена или использована после освобождения во время демонтажа вызывающего абонента.
(OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_sb) пробежал
скопировать поток:
- find_async_copy() переместил копию->refcount, но оставил копию включенной
clp->async_copies, чтобы можно было запустить cleanup_async_copy() жнеца
Release_copy_files() одновременно с вызывающей стороной отмены/завершения работы. оба
поместите и NULL nf_src/nf_dst без общей блокировки, дважды поставив
nfsd_file и досрочно освободите его.
- nfsd4_do_async_copy() устанавливает NFSD4_COPY_F_STOPPED перед его окончательным использованием.
копии (nfsd_update_cmtime_attr() при копировании->nf_dst,
nfsd4_send_cb_offload()). nfsd4_stop_copy() обрабатывает установленный бит STOPPED
как «kthread выполнено, пропустите kthread_stop()», поэтому вызывающий абонент запустил
Release_copy_files() — который помещает и NULL-значения nf_dst — в то время как
kthread все еще разыменовал его (NULL/UAF).
- copy->copy_task никогда не был закреплен. Одноразовый kthread самопожинает
return, чтобы метод get_task_struct() функции kthread_stop() мог коснуться освобожденного
Task_struct.
- co_cb встроен в копию, но nfsd4_send_cb_offload() удерживает
ссылка только на клиенте, поэтому одновременное удаление может освободить
копия, пока выполнялся обратный вызов CB_OFFLOAD.
Исправьте время жизни демонтажа в целом:
- find_async_copy() отключает копию (очистка cp_clp, list_del_init)
под async_lock; пути отмены, выключения и sb-cancel удаляют
Ссылка на членство в списке через nfs4_put_copy() после nfsd4_stop_copy(). Удалите теперь уже избыточное исправление list_del из cleanup_async_copy().
- Поскольку отсоединение скрывает копию от жнеца, ее
Cleanup_async_copy() больше не может удалять s2s_cp_stateids копии.
вход; пути отмены/завершения работы/sb-cancel теперь вызывают
nfs4_free_copy_state() (пока cp_clp все еще действителен), поэтому
запись не болтается при освободившейся памяти для прачечной и
Manage_cpntf_state() для разыменования.
- Дайте kthread собственную ссылку, полученную ранее в nfsd4_copy().
Wake_up_process() и удален в конце nfsd4_do_async_copy();
вызовитеake_up_process() перед list_add().
- Закрепите Task_struct с помощью get_task_struct() в nfsd4_copy(), выпущено.
в nfs4_put_copy(), поэтому kthread_stop() безопасен всякий раз, когда kthread
выходит. Установите NFSD4_COPY_F_STOPPED только в nfsd4_stop_copy(), который теперь
всегда kthread_stop() перед Release_copy_files(); завершение
все еще сообщается через NFSD4_COPY_F_COMPLETED, поэтому
nfsd4_has_active_async_copies() не затрагивается.
Каждый вызывающий абонент
сначала удаляет копию из clp->async_copies, поэтому запускается kthread_stop()
ровно один раз.
- Возьмите ссылку на копию в nfsd4_send_cb_offload(), вставленную в
nfsd4_cb_offload_release(). Kthread по-прежнему содержит собственную ссылку.
там, поэтому refcount_inc() не может участвовать в финальной бесплатной гонке.
- Прочитайте cp_clp с помощью smp_load_acquire() для сопряжения с неупорядоченным
Средства записи set_bit()/clear_bit() (Документация/atomic_bitops.rst).
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An async copy could be freed or used after free while a teardown caller (OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_sb) raced the copy kthread: - find_async_copy() bumped copy->refcount but left the copy on clp->async_copies, so the reaper's cleanup_async_copy() could run release_copy_files() concurrently with a cancel/shutdown caller. Both put and NULL nf_src/nf_dst without a common lock, double-putting the nfsd_file and freeing it early. - nfsd4_do_async_copy() set NFSD4_COPY_F_STOPPED before its final uses of the copy (nfsd_update_cmtime_attr() on copy->nf_dst, nfsd4_send_cb_offload()). nfsd4_stop_copy() treats a set STOPPED bit as "kthread done, skip kthread_stop()", so a teardown caller ran release_copy_files() -- which puts and NULLs nf_dst -- while the kthread still dereferenced it (NULL/UAF). - copy->copy_task was never pinned. The one-shot kthread self-reaps on return, so kthread_stop()'s get_task_struct() could touch a freed task_struct. - co_cb is embedded in the copy, but nfsd4_send_cb_offload() held a reference only on the client, so a concurrent teardown could free the copy while the CB_OFFLOAD callback was in flight. Fix the teardown lifetime as a whole: - find_async_copy() unlinks the copy (clear cp_clp, list_del_init) under async_lock; the cancel, shutdown, and sb-cancel paths drop the list-membership reference via nfs4_put_copy() after nfsd4_stop_copy(). Drop the now-redundant list_del fixup from cleanup_async_copy(). - Because unlinking hides the copy from the reaper, its cleanup_async_copy() can no longer remove the copy's s2s_cp_stateids entry; the cancel/shutdown/sb-cancel paths now call nfs4_free_copy_state() themselves (while cp_clp is still valid) so the entry does not dangle at freed memory for the laundromat and manage_cpntf_state() to dereference. - Give the kthread its own reference, taken in nfsd4_copy() before wake_up_process() and dropped at the end of nfsd4_do_async_copy(); call wake_up_process() before list_add(). - Pin the task_struct with get_task_struct() in nfsd4_copy(), released in nfs4_put_copy(), so kthread_stop() is safe whenever the kthread exits. Set NFSD4_COPY_F_STOPPED only in nfsd4_stop_copy(), which now always kthread_stop()s before release_copy_files(); completion is still reported via NFSD4_COPY_F_COMPLETED, so nfsd4_has_active_async_copies() is unaffected. Each teardown caller removes the copy from clp->async_copies first, so kthread_stop() runs exactly once. - Take a copy reference in nfsd4_send_cb_offload(), dropped in nfsd4_cb_offload_release(). The kthread still holds its own reference there, so the refcount_inc() cannot race the final free. - Read cp_clp with smp_load_acquire() to pair with the unordered set_bit()/clear_bit() writers (Documentation/atomic_bitops.rst).
Характеристики атаки
Последствия
Строка CVSS v3.1