igc: remove napi_synchronize() in igc_down()
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
igc: remove napi_synchronize() in igc_down()
When an AF_XDP zero-copy application is killed abruptly, the XSK pool is
torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the
full budget on every poll, so napi_complete_done() never clears
NAPI_STATE_SCHED.
igc_down() calls napi_synchronize() before napi_disable(), so it spins
forever waiting for that bit and the interface never goes down. Drop the
napi_synchronize() and let napi_disable() do the job -- it sets
NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it
ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after
polling has stopped, matching the recent igb fix b1e067240379.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/3b5aee6fcbf6b58112d40d19c8d31fa3f78ee668https://git.kernel.org/stable/c/5ffab5b9589c50e4cfc0cf36ffd76c89422d4019https://git.kernel.org/stable/c/605585a8d89aaeb0122e9016fdaa92376897a705https://git.kernel.org/stable/c/9a2b637aef4e515c2179774888441d00e8a5ae95https://git.kernel.org/stable/c/a0f16c337691813f8d8f014c01fff5a368e08898https://git.kernel.org/stable/c/ad6e0df267dc96edb7de1fa0a2fb2a70645bff86https://git.kernel.org/stable/c/f929a6fe5b7ae1e72d2c6d18cd69ab90dcf689d2