[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <aCrJ4ftEQ34opaa7@gondor.apana.org.au>
Date: Mon, 19 May 2025 14:04:17 +0800
From: Herbert Xu <herbert@...dor.apana.org.au>
To: Ivan Pravdin <ipravdin.official@...il.com>
Cc: davem@...emloft.net, linux-crypto@...r.kernel.org,
linux-kernel@...r.kernel.org
Subject: Re: [PATCH] crypto: algif_hash - fix double free in hash_accept
On Sun, May 18, 2025 at 06:41:02PM -0400, Ivan Pravdin wrote:
> If accept(2) is called on socket type algif_hash with
> MSG_MORE flag set and crypto_ahash_import fails,
> sk2 is freed. However, it is also freed in af_alg_release,
> leading to slab-use-after-free error.
>
> Fixes: fe869cdb89c9 ("crypto: algif_hash - User-space interface for hash operations")
> Signed-off-by: Ivan Pravdin <ipravdin.official@...il.com>
> ---
> crypto/algif_hash.c | 4 ----
> 1 file changed, 4 deletions(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@...dor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Powered by blists - more mailing lists