ACK: [SRU focal/linux-oem-5.10 0/1] CVE-2021-26708
Tim Gardner
tim.gardner at canonical.com
Mon Mar 1 15:48:13 UTC 2021
On 3/1/21 7:36 AM, Thadeu Lima de Souza Cascardo wrote:
> [Impact]
> vsock multi transport race leads to UAF, which may allow in privilege
> escalation.
>
> [Fix]
> Clean cherry-pick of upstream c518adafa39f.
>
> [Test case]
> Ran a reproducer, gets a WARNING when unpatched, no WARNING when patched.
>
> [Potential regression]
> AF_VSOCK use might break.
>
> Alexander Popov (1):
> vsock: fix the race conditions in multi-transport support
>
> net/vmw_vsock/af_vsock.c | 17 ++++++++++++-----
> 1 file changed, 12 insertions(+), 5 deletions(-)
>
Straightforward fix, clean upstream cherry-pick.
Acked-by: Tim Gardner <tim.gardner at canonical.com>
-----------
Tim Gardner
Canonical, Inc
More information about the kernel-team
mailing list