riscv: Fix register corruption from uninitialized cregs on error
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
riscv: Fix register corruption from uninitialized cregs on error
compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when
user_regset_copyin() fails. Since cregs is an uninitialized stack
variable, a copyin failure causes uninitialized stack data to be written
into the target task's pt_regs, corrupting its register state and
potentially leaking kernel stack contents.
compat_restore_sigcontext() has the same issue: it calls cregs_to_regs()
even when __copy_from_user() fails, leading to the same corruption of
the signal-returning task's register state on error.
Only call cregs_to_regs() when the user copy succeeds.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/0599aa23734c48de9bce36d043a9ec90c23945a1https://git.kernel.org/stable/c/2a7d1daf2674fe7d5b1cc99a4e3b5f0f72d5958fhttps://git.kernel.org/stable/c/66dedb6028c3df6c6a3372dd935b823917e150d5https://git.kernel.org/stable/c/6ebcbb53fc9bc30843054ed99fd60b8e542628f4https://git.kernel.org/stable/c/9e020156833f1ad0d425a1e3d85b65639f1c1c50https://git.kernel.org/stable/c/f2d88b0d7aebfa4643fc58bbae57210c6daff9c6