В ядре Linux устранена следующая уязвимость:
nfsd: исправлена гонка двойной ссылки работника макета ограждения
Ядро рабочей очереди очищает WORK_STRUCT_PENDING перед обратным вызовом.
вызывается, поэтому функция Delayed_work_pending() в lm_breaker_timedout() может
верните false, пока рабочий забора уже запущен. Это позволяет
прерыватель возьмет дубликат ссылки sc_count и запланирует новую
рабочий, который объединяется с незавершенным. Дополнительная ссылка
никогда не ставится, утечка макета.
Замените пикантную проверку Delayed_work_pending() на проверку
ls_fence_inflight логическое значение устанавливается атомарно с помощью
refcount_inc_not_zero() в ls_lock и очищается в ls_lock
перед последним вызовом nfs4_put_stid() на пути удаления; повторная попытка
путь намеренно сохраняет его. Удалить самоперевооружение
mod_delayed_work() в верхней части работника.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference race The workqueue core clears WORK_STRUCT_PENDING before the callback is invoked, so delayed_work_pending() in lm_breaker_timedout() can return false while the fence worker is already running. This lets the breaker take a duplicate sc_count reference and schedule a new worker that coalesces with the in-progress one. The extra reference is never put, leaking the layout stateid. Replace the racy delayed_work_pending() check with an ls_fence_inflight boolean set atomically with refcount_inc_not_zero() under ls_lock, and cleared under ls_lock before the final nfs4_put_stid() on the dispose path; the retry path intentionally retains it. Remove the self-rearm mod_delayed_work() at the top of the worker.
Характеристики атаки
Последствия
Строка CVSS v3.1