From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D830158D66 for ; Thu, 29 Feb 2024 15:53:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709222022; cv=none; b=b5+B/3/G83MW+VAy1xr7eAycgBJYyVz9rdGdvH1evbc/nImuD9n2OUxUmSk3TPx7e2s6R4tawRHciIwXHeldF0b4geKwEF2r4jOyTReyHYLZtebsvEQ5+B6eJ3EJVXBaQEIyX3u0oXxEOjaRIQtCGF2Xh63tlxCMpq7lSHCctls= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709222022; c=relaxed/simple; bh=+wNRRr7LA9bNKofwQOj5I9DhV1s/4EfeEYQuoZlMWjQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=g/RFt2l6Bm/rMdbaNJN1tvewZgDQ1FOjcpzu26i01jC3d9bDW3VBlGVFbcMffKFmn4fh9DQjecdKWPQCbN+pDrNBhROiDrxxHdVgF2Tp9Ms+Q29nsLm2Tiyig/BksV+zmTpJ2oSeBIgykJvYn/rmzbPI7eUUvz5SzFKsJKPbPuc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=r5oWEhaZ; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="r5oWEhaZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 69E12C43390; Thu, 29 Feb 2024 15:53:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1709222021; bh=+wNRRr7LA9bNKofwQOj5I9DhV1s/4EfeEYQuoZlMWjQ=; h=From:To:Cc:Subject:Date:Reply-to:From; b=r5oWEhaZXkBnzYcYkgXly/cJF5NdweXpmHI3U1Dr2TyH+jdPx6UBkaK41urHAqVpj +X63xYn9PVm0gbDX3BcMu8rjdMsNIsdHFgYyVnesftTfG8T2yu0zn4uscTtymKvwv5 FeRzoxgDB+PctmjUgrQuIyI56k/98vpainnjHdVgs1Kwm9O/+JbYn33kn7tf+DGTN5 JfBLLcWCW6ueTc4FvtIa6XYaRnporbY07laJdqTdAspGnm9eEnlyLta8w/XjNsUFQd We4wZZOcu8JHD3eB2KZL18ja2zcn1Mr3qxnIO+XaafPesfkk2E2mmDBR80xpKFPv9m 5E5weyHuBTBqg== From: Lee Jones To: linux-cve-announce@vger.kernel.org Cc: Lee Jones Subject: CVE-2024-26619: riscv: Fix module loading free order Date: Thu, 29 Feb 2024 15:53:10 +0000 Message-ID: <20240229155245.1571576-51-lee@kernel.org> X-Mailer: git-send-email 2.44.0.rc1.240.g4c46232300-goog Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=1694; i=lee@kernel.org; h=from:subject; bh=+wNRRr7LA9bNKofwQOj5I9DhV1s/4EfeEYQuoZlMWjQ=; b=owEBbQKS/ZANAwAKAVGvii+H/HdhAcsmYgBl4KhQIbD96R2/UVuvKR5yx8pv9rl7If16tRmlt mLHYC9pB6eJAjMEAAEKAB0WIQR2tsk1o74gmpTwh0hRr4ovh/x3YQUCZeCoUAAKCRBRr4ovh/x3 YSdsD/sHueASwlCClvH3S0JTFZNehd8G/5Pf2nKTezburLGHSe3eYMCB345fGjO6JtgVnRgjLl8 /o0nsUlldIUsGmiIcius91Ha4Pgt21g5O4zjUN7RqGdmgTRRKnT8K5AOwzYdzFZBDgNtkWBNtxd GPP/ntpsh50oAinDAzy7hjXKGJ4ho3mjYcwq6ZV2Higw63TujVDF8fDmk++dxITB8QSoz3Ay9Vn PXkKtQaXS0m6VG5G+nLG15z2dXe9Hy2HfX0kCT9rIdGr0UMIazIPGn/ddBtkwgHxqrqGkVUEY08 26S2Yu258dmCXsnqknlKUXTcnwicVL8I2tiqOiWV9DYIkqxN8vwm10GAtod7hMXbmOpwke/L8+Q jVfnNLS5GEWZj1aXG+OLM35M83zGBcFMofckMiGgCQWsT0foHUdQbJIlHqccjj2d3M/hE+uFIMw fhiGmN5nskjFof6o78N1TJURVOl8TXfEgsFnz/o5JNJbFTIxMkj3ZPWasI+BOJYtjQQeYQIIbhu PmiC/+igxDc9lFmn5Llf4Yw9RL9rHOsl634uKLsdOxJalexkBSETCRiAE9aBP7knLrRWgdDxHH6 2AfHexOCQet69XgC2J3+MzxWLjJu+TVV3PQEs5hktm/fnJ01zzJjaZo4vjkuOZ5AZc4XLAsZj5i ExL1oSvoYQQWtZQ== X-Developer-Key: i=lee@kernel.org; a=openpgp; fpr=76B6C935A3BE209A94F0874851AF8A2F87FC7761 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: riscv: Fix module loading free order Reverse order of kfree calls to resolve use-after-free error. The Linux kernel CVE team has assigned CVE-2024-26619 to this issue. Affected and fixed versions =========================== Issue introduced in 6.7 with commit d8792a5734b0 and fixed in 6.7.3 with commit 2fa79badf4bf Issue introduced in 6.7 with commit d8792a5734b0 and fixed in 6.8-rc1 with commit 78996eee79eb Please see https://www.kernel.org or a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-26619 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: arch/riscv/kernel/module.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2fa79badf4bfeffda6b5032cf62b828486ec9a99 https://git.kernel.org/stable/c/78996eee79ebdfe8b6f0e54cb6dcc792d5129291