lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Wed, 13 Apr 2022 13:50:11 +0000 From: patchwork-bot+netdevbpf@...nel.org To: Lin Ma <linma@....edu.cn> Cc: krzk@...nel.org, davem@...emloft.net, kuba@...nel.org, pabeni@...hat.com, netdev@...r.kernel.org, linux-kernel@...r.kernel.org, mudongliangabcd@...il.com Subject: Re: [PATCH v0] nfc: nci: add flush_workqueue to prevent uaf Hello: This patch was applied to netdev/net.git (master) by David S. Miller <davem@...emloft.net>: On Wed, 13 Apr 2022 00:04:30 +0800 you wrote: > Our detector found a concurrent use-after-free bug when detaching an > NCI device. The main reason for this bug is the unexpected scheduling > between the used delayed mechanism (timer and workqueue). > > The race can be demonstrated below: > > Thread-1 Thread-2 > | nci_dev_up() > | nci_open_device() > | __nci_request(nci_reset_req) > | nci_send_cmd > | queue_work(cmd_work) > nci_unregister_device() | > nci_close_device() | ... > del_timer_sync(cmd_timer)[1] | > ... | Worker > nci_free_device() | nci_cmd_work() > kfree(ndev)[3] | mod_timer(cmd_timer)[2] > > [...] Here is the summary with links: - [v0] nfc: nci: add flush_workqueue to prevent uaf https://git.kernel.org/netdev/net/c/ef27324e2cb7 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html
Powered by blists - more mailing lists