From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 344311C7B64 for ; Mon, 21 Oct 2024 20:12:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729541520; cv=none; b=TlBRpVv5pK4wvQV+184XmqBFCxJRzCxTDN6zz8dcKWcnlnkR7ptMUDhfsCiPLOpMFDY6fxRqEpiBQfCwVatTRttAVIxmrwnjxTBQtgpwoCTjugguQmoveWE47WtzT+6sE+GFxLa2N5y3iYYbco6yxp78cvMubUDgm+fDxbKkzf0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729541520; c=relaxed/simple; bh=UjkwvFp8Z9VXqoK48s3EhI7eD6vGJqio4bRtRgkg//A=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ox+3fCyarXetWVi1T/29rNqKOFz5lO1ps9IHJN/8p1m0jM3m0r3jBxdhx/PFuN6MOUGLsiSot8ouhJ940W90tsSL4hMH9H1iRGz0Kqnsv8ig5cyu+C1LMPXPiRfMjtn0cOlX/E/RkHUjfxZzUNYFCG7tJ8MS6F/CbhBqoe57O7Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=tvg/Ldvq; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="tvg/Ldvq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9BEDFC4CEC3; Mon, 21 Oct 2024 20:11:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1729541520; bh=UjkwvFp8Z9VXqoK48s3EhI7eD6vGJqio4bRtRgkg//A=; h=From:To:Cc:Subject:Date:Reply-to:From; b=tvg/Ldvq//V7aUp9nM2wrmgzPnQnOER/ZDPLX0Id37IyscLYeDYE6CLm4swNIcAaU R6DPFPCBElB4qmBRf8lchqspZlDT/Lu418cR+HK/TH2SogKSpgr2t76rXM+qTVclL0 PtOEuiQwy0ul9mFk1n+GHgeSLvhEiVX0YlHnW594= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-48984: can: slcan: fix freed work crash Date: Mon, 21 Oct 2024 22:06:16 +0200 Message-ID: <2024102147-CVE-2022-48984-ea9e@gregkh> X-Mailer: git-send-email 2.47.0 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3997; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=UjkwvFp8Z9VXqoK48s3EhI7eD6vGJqio4bRtRgkg//A=; b=owGbwMvMwCRo6H6F97bub03G02pJDOliW6QjK4rThBs8Kg8+vj7j4BpHwU1WH/57/85Yo9B3d OqMT3m6HbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRc6wM8yMWttYuVZVt+T6x TYT3z+8FQjWtOgwLDm2JDNz0vvXIROFVpsorJws8uq90DQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: can: slcan: fix freed work crash The LTP test pty03 is causing a crash in slcan: BUG: kernel NULL pointer dereference, address: 0000000000000008 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 0 PID: 348 Comm: kworker/0:3 Not tainted 6.0.8-1-default #1 openSUSE Tumbleweed 9d20364b934f5aab0a9bdf84e8f45cfdfae39dab Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b-rebuilt.opensuse.org 04/01/2014 Workqueue: 0x0 (events) RIP: 0010:process_one_work (/home/rich/kernel/linux/kernel/workqueue.c:706 /home/rich/kernel/linux/kernel/workqueue.c:2185) Code: 49 89 ff 41 56 41 55 41 54 55 53 48 89 f3 48 83 ec 10 48 8b 06 48 8b 6f 48 49 89 c4 45 30 e4 a8 04 b8 00 00 00 00 4c 0f 44 e0 <49> 8b 44 24 08 44 8b a8 00 01 00 00 41 83 e5 20 f6 45 10 04 75 0e RSP: 0018:ffffaf7b40f47e98 EFLAGS: 00010046 RAX: 0000000000000000 RBX: ffff9d644e1b8b48 RCX: ffff9d649e439968 RDX: 00000000ffff8455 RSI: ffff9d644e1b8b48 RDI: ffff9d64764aa6c0 RBP: ffff9d649e4335c0 R08: 0000000000000c00 R09: ffff9d64764aa734 R10: 0000000000000007 R11: 0000000000000001 R12: 0000000000000000 R13: ffff9d649e4335e8 R14: ffff9d64490da780 R15: ffff9d64764aa6c0 FS: 0000000000000000(0000) GS:ffff9d649e400000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 0000000036424000 CR4: 00000000000006f0 Call Trace: worker_thread (/home/rich/kernel/linux/kernel/workqueue.c:2436) kthread (/home/rich/kernel/linux/kernel/kthread.c:376) ret_from_fork (/home/rich/kernel/linux/arch/x86/entry/entry_64.S:312) Apparently, the slcan's tx_work is freed while being scheduled. While slcan_netdev_close() (netdev side) calls flush_work(&sl->tx_work), slcan_close() (tty side) does not. So when the netdev is never set UP, but the tty is stuffed with bytes and forced to wakeup write, the work is scheduled, but never flushed. So add an additional flush_work() to slcan_close() to be sure the work is flushed under all circumstances. The Fixes commit below moved flush_work() from slcan_close() to slcan_netdev_close(). What was the rationale behind it? Maybe we can drop the one in slcan_netdev_close()? I see the same pattern in can327. So it perhaps needs the very same fix. The Linux kernel CVE team has assigned CVE-2022-48984 to this issue. Affected and fixed versions =========================== Issue introduced in 6.0 with commit cfcb4465e992 and fixed in 6.0.13 with commit 9e2709d58a14 Issue introduced in 6.0 with commit cfcb4465e992 and fixed in 6.1 with commit fb855e9f3b6b Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-48984 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/can/slcan/slcan-core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9e2709d58a14a10eb00d919acd7dec071c33f8c8 https://git.kernel.org/stable/c/fb855e9f3b6b42c72af3f1eb0b288998fe0d5ebb