misc: pci_endpoint_test: Free IRQs before removing the device
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
misc: pci_endpoint_test: Free IRQs before removing the device
In pci_endpoint_test_remove(), freeing the IRQs after removing the device
creates a small race window for IRQs to be received with the test device
memory already released, causing the IRQ handler to access invalid memory,
resulting in an oops.
Free the device IRQs before removing the device to avoid this issue.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/14bdee38e96c7d37ca15e7bea50411eee25fe315https://git.kernel.org/stable/c/38d12bcf4e2ce3d285eb29644a79a54f42040fabhttps://git.kernel.org/stable/c/c2dba13bc0c62b79a3cbe4bfe5faa32231bf9b55https://git.kernel.org/stable/c/cdf9a7e2cdc7a5464e3cc6d0b715ba2b1d215521https://git.kernel.org/stable/c/dd2210379205fcd23a9d8869b0cef90e3770577chttps://git.kernel.org/stable/c/f61b7634a3249d12b9daa36ffbdb9965b6f24c6chttps://git.kernel.org/stable/c/fb7f8bdb886f2ebf35ee5edaf2bf5f02b063ddb7