From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DBE8B84FB0 for ; Fri, 24 May 2024 15:13:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716563581; cv=none; b=rTt7B5kNRnansxyD4zKfFiRAT2/7RiHl6EImVJN1VLhwffDXmvPTFp3mlbdaymRBfpyGOlW91n0IvLQ9zRj4UC/rCtH/UfyB/Yr+iMPsSMGpEnz7UXgkTfnubGPIbqfSdABVFl5uGLJbES9GA90k3cVt6/nHKuWRLh4pDGNKOW8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716563581; c=relaxed/simple; bh=Fyq0B9Wc/OTS1aUXB0eMtiY2kq7Jl5r1VDg4JZhhHM0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IXUz89y3JrXmxSkOErvX4Z2JEOiVZp2/g4QHtyekoPspjlKgrD4AwwWIUfpJslqBmZr79yLrsOSLaCRW8inrwAECZ07tV2t73hDWLP4b9sRYW4kAKBCNqV1jXvayRqXXGgCXw4CQij316uBlulq5OxV0NgqpVlYNFWnJsIAISQo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=WP06CaBd; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="WP06CaBd" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5B768C2BBFC; Fri, 24 May 2024 15:13:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1716563581; bh=Fyq0B9Wc/OTS1aUXB0eMtiY2kq7Jl5r1VDg4JZhhHM0=; h=From:To:Cc:Subject:Date:Reply-to:From; b=WP06CaBdjaEwk78/NSXw2w3rpF1nmBPOs7QpDa5BRx5+EiQBIbged/c7vLgcYYEd4 /TskWGG/QCyUhYAz/vt9t56d8+UXSLgHoXVYtfxzpmL0tMdaFsBcZPgifY1RtXNXou oJ4VxCLVl2vjWiyyfHI+w7OUl6KOw1ai1jU+j7Qg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2021-47559: net/smc: Fix NULL pointer dereferencing in smc_vlan_by_tcpsk() Date: Fri, 24 May 2024 17:12:51 +0200 Message-ID: <2024052450-CVE-2021-47559-9909@gregkh> X-Mailer: git-send-email 2.45.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2533; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Fyq0B9Wc/OTS1aUXB0eMtiY2kq7Jl5r1VDg4JZhhHM0=; b=owGbwMvMwCRo6H6F97bub03G02pJDGkB64qvG0bO14sw6Jj7w0v8waJ/D/TaKnnTOjMT7c5pp FhIWzd1xLIwCDIxyIopsnzZxnN0f8UhRS9D29Mwc1iZQIYwcHEKwERMtjMsmL7yBIfAz7oJYf8q pyVt6vNfqd73g2HB5NVZi15JN79Jj7/reWNP9YX2rMBEAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereferencing in smc_vlan_by_tcpsk() Coverity reports a possible NULL dereferencing problem: in smc_vlan_by_tcpsk(): 6. returned_null: netdev_lower_get_next returns NULL (checked 29 out of 30 times). 7. var_assigned: Assigning: ndev = NULL return value from netdev_lower_get_next. 1623 ndev = (struct net_device *)netdev_lower_get_next(ndev, &lower); CID 1468509 (#1 of 1): Dereference null return value (NULL_RETURNS) 8. dereference: Dereferencing a pointer that might be NULL ndev when calling is_vlan_dev. 1624 if (is_vlan_dev(ndev)) { Remove the manual implementation and use netdev_walk_all_lower_dev() to iterate over the lower devices. While on it remove an obsolete function parameter comment. The Linux kernel CVE team has assigned CVE-2021-47559 to this issue. Affected and fixed versions =========================== Issue introduced in 4.18 with commit cb9d43f67754 and fixed in 5.10.83 with commit c94cbd262b6a Issue introduced in 4.18 with commit cb9d43f67754 and fixed in 5.15.6 with commit bb851d0fb025 Issue introduced in 4.18 with commit cb9d43f67754 and fixed in 5.16 with commit 587acad41f1b Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2021-47559 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/smc/smc_core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/c94cbd262b6aa3b54d73a1ed1f9c0d19df57f4ff https://git.kernel.org/stable/c/bb851d0fb02547d03cd40106b5f2391c4fed6ed1 https://git.kernel.org/stable/c/587acad41f1bc48e16f42bb2aca63bf323380be8