APPLIED [OEM-6.0] Re: [UBUNTU Kinetic,OEM-6.0 0/1] CVE-2023-0469
Timo Aaltonen
tjaalton at ubuntu.com
Fri Feb 10 10:27:31 UTC 2023
Thadeu Lima de Souza Cascardo kirjoitti 9.2.2023 klo 20.46:
> [Impact]
> A double fput on io_uring may lead to a use-after-free condition.
>
> [Potential regression]
> io_uring might be broken, lead to kernel lockups, crashes, or memory leaks.
>
> [Further review]
> In both cases, all the callers were looked up for any extra fput, all were
> considered safe.
>
> [Testing]
> io_uring programs exercising the path were used, also under memcg, exercising
> memory allocation failure conditions.
>
> Lin Ma (1):
> io_uring/filetable: fix file reference underflow
>
> io_uring/filetable.c | 2 --
> 1 file changed, 2 deletions(-)
>
applied to oem-6.0, thanks
--
t
More information about the kernel-team
mailing list