В ядре Linux устранена следующая уязвимость:
lockd, nfsd: отправка nlmsvc_ops с защитой RCU
nlmsvc_ops публикуется функцией nfsd_lockd_init() и очищается функцией
nfsd_lockd_shutdown() с простыми хранилищами, а lockd разыменовывает
он не защищен от сайтов отправки в fs/lockd/svcsubs.c. Указатель
нацелен на .rodata nfsd, а обратные вызовы fopen/fclose живут в nfsd
.text, поэтому устаревшая загрузка после rmmod nfsd приводит либо к NULL
deref или текст модуля use-after-free. Объявите nlmsvc_ops как __rcu, опубликуйте через rcu_assign_pointer(), очистите
через RCU_INIT_POINTER() +sync_rcu().
Добавьте модуль структуры
*поле владельца в nlmsvc_binding и закрепите модуль через косвенный
вызовы с помощью try_module_get/module_put. Когда переплет рвется,
вернитесь к fput(), чтобы избежать утечки ссылок на файлы структуры.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsvc_ops is published by nfsd_lockd_init() and cleared by nfsd_lockd_shutdown() with plain stores, while lockd dereferences it unguarded from dispatch sites in fs/lockd/svcsubs.c. The pointer targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's .text, so a stale load after rmmod nfsd results in either a NULL deref or a module-text use-after-free. Declare nlmsvc_ops as __rcu, publish via rcu_assign_pointer(), clear via RCU_INIT_POINTER() + synchronize_rcu(). Add a struct module *owner field to nlmsvc_binding and pin the module across indirect calls with try_module_get/module_put. When the binding is torn down, fall back to fput() to avoid leaking struct file references.
Характеристики атаки
Последствия
Строка CVSS v3.1