APPLIED [OEM-6.0] Re: [UBUNTU Kinetic,OEM-6.0 0/1] CVE-2023-0469

Timo Aaltonen tjaalton at ubuntu.com
Fri Feb 10 10:27:31 UTC 2023


Thadeu Lima de Souza Cascardo kirjoitti 9.2.2023 klo 20.46:
> [Impact]
> A double fput on io_uring may lead to a use-after-free condition.
> 
> [Potential regression]
> io_uring might be broken, lead to kernel lockups, crashes, or memory leaks.
> 
> [Further review]
> In both cases, all the callers were looked up for any extra fput, all were
> considered safe.
> 
> [Testing]
> io_uring programs exercising the path were used, also under memcg, exercising
> memory allocation failure conditions.
> 
> Lin Ma (1):
>    io_uring/filetable: fix file reference underflow
> 
>   io_uring/filetable.c | 2 --
>   1 file changed, 2 deletions(-)
> 

applied to oem-6.0, thanks

-- 
t




More information about the kernel-team mailing list