ACK: [SRU][OEM-5.17][OEM-6.0][PATCH 0/1] CVE-2023-1118

Marcelo Henrique Cerri marcelo.cerri at canonical.com
Tue Mar 28 17:45:23 UTC 2023


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


LGTM

On Mon, Mar 27 2023, Magali Lemes wrote:
> [Impact]
> A flaw use after free in the Linux kernel integrated infrared
> receiver/transceiver driver was found in the way user detaching rc device. A
> local user could use this flaw to crash the system or potentially escalate
> their privileges on the system.
>
> [Backport]
> Clean cherry-pick.
>
> [Test]
> Compiled, boot and module load tested.
>
> [Regression potential]
> Minimal, since we're only unregistering the RC device and adding
> del_timer_sync() to deactivate the tx_sim_timer timer as first actions in the
> ene_remove() function. Regressions would possibly only affect users of the
> infrared receiver/transceiver made by ENE.
>
> Duoming Zhou (1):
>   media: rc: Fix use-after-free bugs caused by ene_tx_irqsim()
>
>  drivers/media/rc/ene_ir.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
>
> --
> 2.34.1


Acked-by: Marcelo Henrique Cerri <marcelo.cerri at canonical.com>

- --
Regards,
Marcelo
-----BEGIN PGP SIGNATURE-----

iQHQBAEBCgA6FiEExJjLjAfVL0XbfEr56e82LoessAkFAmQjJ8IcHG1hcmNlbG8u
Y2VycmlAY2Fub25pY2FsLmNvbQAKCRDp7zYuh6ywCc/iC/9rERxQNMTwB9jG3CSL
VDrEVnUzWiPUqMp1HVWMAB/tUYXEo7wzguCx2zn2UkdHKo3+eDKpJoXiqJQiyHcm
Jj36M/uLL7hlGDPrz76oeiHmE4qcaisvA0/0KFSWBKw5EWI3Ww+KEyXr7YFckYUM
Kgft9qjD0yPzjQhJu6d2vamN9e7bQkDeiRGTMy6IhlkfShEgJVPXy7XtpLCiqFI9
3QNMs5Sh3XcKbaSd3o6fzkXRm/btGTAY/k4EERjDFlWge1Z9VbmiBwws9gzHTIFH
PBEkP6c93MtWCYKcmFqdfKcjUZgi7GBJWqH6achJtDYDhpFUe5MkCExKyjD42J+b
m4X7dmy/i6JSLaRjObQVUxWrvycIS253DBXwpFw+iU3NIjwwjuSIV1b3YZBemeun
F0VFMY9rMYxgKX5LRaXvDQstCQr+nGtTJ45syDN4uIagdI52gJq3zzU54JCX1jgH
ZY39eQ4C60M7NW+53mq0Y62zHGfyL7pXLmGhdMbpskikfJc=
=rtci
-----END PGP SIGNATURE-----



More information about the kernel-team mailing list