net: slip: serialize receive against buffer reallocation
0Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Track
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
net: slip: serialize receive against buffer reallocation
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.
An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.
Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73cehttps://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fdhttps://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d