All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: Michal Hocko <mhocko@suse.com>
Cc: cve@kernel.org, linux-kernel@vger.kernel.org,
	Jason Xing <kernelxing@tencent.com>,
	linux-cve-announce@vger.kernel.org
Subject: Re: CVE-2024-27429: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser
Date: Wed, 22 May 2024 07:11:28 +0200	[thread overview]
Message-ID: <2024052219-storewide-arrogance-8d54@gregkh> (raw)
In-Reply-To: <ZkzGL_vXciG7ipm5@tiehlicka>

On Tue, May 21, 2024 at 06:05:03PM +0200, Michal Hocko wrote:
> On Tue 21-05-24 16:40:24, Greg KH wrote:
> > On Tue, May 21, 2024 at 10:39:04AM +0200, Michal Hocko wrote:
> > > This and couple of others are all having the same pattern. Adding
> > > READ_ONCE for an integer value with a claim that this might race with
> > > sysctl updates. While the claim about the race is correct I fail to see
> > > how this could have any security consequences. Even if a partial write
> > > was observed which sounds _more_ than theoretical these all are merely
> > > timeouts and delays.
> > > 
> > > Is there anything I am missing?
> > 
> > Nope, you are right, our fault, I'll go revoke this now.
> 
> please also revoke all others touching the same function.

I don't see any other CVEs that reference that function, but I do see
some that reference the same type of issue in the same file:
	CVE-2024-27420
	CVE-2024-27421
	CVE-2024-27430
are those what you are referring to?  If not, which ones do you think
also should be revoked?

thanks,

greg k-h

  reply	other threads:[~2024-05-22  5:11 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-05-17 12:02 CVE-2024-27429: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser Greg Kroah-Hartman
2024-05-21  8:39 ` Michal Hocko
2024-05-21 14:40   ` Greg Kroah-Hartman
2024-05-21 16:05     ` Michal Hocko
2024-05-22  5:11       ` Greg Kroah-Hartman [this message]
2024-05-22 10:21         ` Davide Benini
2024-05-24 11:27           ` Michal Hocko
2024-05-25 13:28             ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2024052219-storewide-arrogance-8d54@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=kernelxing@tencent.com \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mhocko@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.