Описание
In the Linux kernel, the following vulnerability has been resolved:
iio: buffer: Tie IIO dma fence lock lifetime to the fence
The iio_dma_fence implementation currently uses a lock embedded in the
iio_dmabuf_priv. But the iio_dma_fence can outlive the
iio_dmabuf_priv, which can cause a use-after-free.
Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct.
We can't just hold a reference to the iio_dmabuf_priv from the
iio_dma_fence since iio_buffer_dmabuf_release() might sleep and the
fence release callback is not allowed to sleep.
Note that the dma_fence framework now has an internal lock that gets used
when the passing NULL for lock in dma_fence_init(), but in order to
allow this patch to be backportable use an external lock.
EPSS
7.8 High
CVSS3
Дефекты
Связанные уязвимости
(In the Linux kernel, the following vulnerability has been resolved: i ...)
In the Linux kernel, the following vulnerability has been resolved: i ...
In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Tie IIO dma fence lock lifetime to the fence The `iio_dma_fence` implementation currently uses a lock embedded in the `iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the `iio_dmabuf_priv`, which can cause a use-after-free. Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct. We can't just hold a reference to the `iio_dmabuf_priv` from the `iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the fence release callback is not allowed to sleep. Note that the `dma_fence` framework now has an internal lock that gets used when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to allow this patch to be backportable use an external lock.
EPSS
7.8 High
CVSS3