From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 996FC16C850 for ; Thu, 27 Feb 2025 02:09:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740622150; cv=none; b=rcuxXksC4tuoloSaouM9gDHoZEzF7uX4gd+YAPNVWeMOz7sPUrwEUO7Qfq7WJ2J8Riyoy2a1FFigu4hajSL9n+H80K8+oUs7SzD3YwXxClqH06TaIQV+DrMy3QEBmtKAa9vGmmFtCmPTtpGHHUXNAX4Y+t67Pam8p+kMsOmdpS4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740622150; c=relaxed/simple; bh=MyGsIz/4h8VKoo3yU3osX1CxOST2KrLAK7vmbUW6+Pw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=KVX4rPtYyfC7XlSwgjJBsV2DdDKn3XRN7xdAi/bbWzOIWrH/ptClRjF0Sbtjme8TS3xu2GVfOmrkdtwA8EksM5/LY9WPjCp8BCyQQOwoNeNAITHukTLsxVeNjDj/iCyKWXC0Ja4L1in8n+TM6I5ak0apXXi7pKsC1pFgDEz0NLs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=O2YU+D2O; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="O2YU+D2O" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 70EDEC4CED6; Thu, 27 Feb 2025 02:09:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740622150; bh=MyGsIz/4h8VKoo3yU3osX1CxOST2KrLAK7vmbUW6+Pw=; h=From:To:Cc:Subject:Date:Reply-to:From; b=O2YU+D2OhogiSdUFxvZ+vyNmX/GDAcnz+7qDfvgBXki4nWoMPdY2p8BX6cQPEJcpy Aqrg6eu86Rmc6VgUikfGnY4ioMkk/n/Mw8EJx7+9g5BwX3XYaeSC4n36mly3byb3Q1 Rp/DnfUnnCxB9TJ/byTQsp/rUn+GSn4dRA03fCrg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2025-21718: net: rose: fix timer races against user threads Date: Wed, 26 Feb 2025 18:06:13 -0800 Message-ID: <2025022646-CVE-2025-21718-d976@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=4008; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=MyGsIz/4h8VKoo3yU3osX1CxOST2KrLAK7vmbUW6+Pw=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7T1QlWsx+EySaLmzBK/NkYQPXa44nRl4fT1ZpW2xkj FDS2jWnI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACYSOYlhvsOPeUulD3G17ti5 vq1XnbFV6uzBWIa54gtdIp+2337VznFVeNWadeZKHbVSAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Rose timers only acquire the socket spinlock, without checking if the socket is owned by one user thread. Add a check and rearm the timers if needed. BUG: KASAN: slab-use-after-free in rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174 Read of size 2 at addr ffff88802f09b82a by task swapper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.13.0-rc5-syzkaller-00172-gd1bf27c4e176 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x169/0x550 mm/kasan/report.c:489 kasan_report+0x143/0x180 mm/kasan/report.c:602 rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174 call_timer_fn+0x187/0x650 kernel/time/timer.c:1793 expire_timers kernel/time/timer.c:1844 [inline] __run_timers kernel/time/timer.c:2418 [inline] __run_timer_base+0x66a/0x8e0 kernel/time/timer.c:2430 run_timer_base kernel/time/timer.c:2439 [inline] run_timer_softirq+0xb7/0x170 kernel/time/timer.c:2449 handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:561 __do_softirq kernel/softirq.c:595 [inline] invoke_softirq kernel/softirq.c:435 [inline] __irq_exit_rcu+0xf7/0x220 kernel/softirq.c:662 irq_exit_rcu+0x9/0x30 kernel/softirq.c:678 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1049 The Linux kernel CVE team has assigned CVE-2025-21718 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.1.129 with commit f55c88e3ca5939a6a8a329024aed8f3d98eea8e4 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.6.76 with commit 51c128ba038cf1b79d605cbee325919b45ab95a5 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.12.13 with commit 1992fb261c90e9827cf5dc3115d89bb0853252c9 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.13.2 with commit 58051a284ac18a3bb815aac6289a679903ddcc3f Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.14-rc1 with commit 5de7665e0a0746b5ad7943554b34db8f8614a196 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2025-21718 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/rose/rose_timer.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/f55c88e3ca5939a6a8a329024aed8f3d98eea8e4 https://git.kernel.org/stable/c/51c128ba038cf1b79d605cbee325919b45ab95a5 https://git.kernel.org/stable/c/1992fb261c90e9827cf5dc3115d89bb0853252c9 https://git.kernel.org/stable/c/58051a284ac18a3bb815aac6289a679903ddcc3f https://git.kernel.org/stable/c/5de7665e0a0746b5ad7943554b34db8f8614a196