net: slip: serialize receive against buffer reallocation
0Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Track
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
net: slip: serialize receive against buffer reallocation
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.
An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.
Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.
Productos afectados
Linux · LinuxReferencias
https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73cehttps://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fdhttps://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d