All of lore.kernel.org
 help / color / mirror / Atom feed
From: Junjie Cao <junjie.cao@linux.dev>
To: openembedded-core@lists.openembedded.org
Cc: paul@pbarker.dev, randy.macleod@windriver.com,
	Venkata.Navuduri@windriver.com
Subject: [OE-core][PATCH v2 05/10] cve-exclusion: set status for CVE-2022-1247
Date: Mon,  3 Aug 2026 01:48:22 -0700	[thread overview]
Message-ID: <20260803084827.1348810-6-junjie.cao@linux.dev> (raw)
In-Reply-To: <20260803084827.1348810-1-junjie.cao@linux.dev>

The CVE describes a race between rose_connect() and the code that frees
a rose_neigh once its count and use fields reach zero.

Takamitsu Iwai's August 2025 series converts that field to a proper
reference count and removes the unlocked increment in rose_connect()
which is exactly the operation the CVE describes:

  https://git.kernel.org/linus/d860d1faa6b2ce3becfdb8b0c2b048ad31800061
  ("net: rose: convert 'use' field to refcount_t", v6.17)

  https://git.kernel.org/linus/da9c9c877597170b929a6121a68dcd3dd9a80f45
  ("net: rose: include node references in rose_neigh refcount", v6.17)

The first commit message states the premise of the CVE almost verbatim:
"The 'use' field in struct rose_neigh is used as a reference counter but
lacks atomicity. This can lead to race conditions where a rose_neigh
structure is freed while still being referenced by other code paths",
and its diff deletes the "rose->neighbour->use++;" statement from
rose_connect(). The second merges the separate count and use counters,
which is the other half of the condition described by the CVE, and
closes a syzbot-reported slab-use-after-free.

Both are in v6.17 and were backported to 6.1.y, 6.6.y, 6.12.y and
6.16.y in the 2025-09-02 stable round.

Kernels from v7.1 onwards are unaffected by construction, since the AX.25
and hamradio subsystems were removed:

  https://git.kernel.org/linus/dd8d4bc28ad7252610d8e79c1313a2d1e3499a51

The commits predate the association of this CVE with
any fix, so no tracker links them yet - Ubuntu, Debian and Red Hat all
still show the CVE as open. The identification above is based on the
commit contents matching the CVE description; the two 2022 rose patches
from Duoming Zhou that Ubuntu's tracker references fix different rose
bugs and are not the fix for this issue.

CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
  list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
  of leaving them undocumented
- disclosed AI assistance per the contributor guide

v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/

 meta/recipes-kernel/linux/cve-exclusion.inc | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index 0ae3a0d6..7547cdfd 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -219,3 +219,9 @@ several attempts, exploitation requires a relative kernel.core_pattern"
 # https://bugzilla.redhat.com/show_bug.cgi?id=2044575
 CVE_STATUS[CVE-2022-0400] = "disputed: the reported net/smc out-of-bounds read \
 was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian"
+
+# Fix https://git.kernel.org/linus/d860d1faa6b2ce3becfdb8b0c2b048ad31800061
+# Fix https://git.kernel.org/linus/da9c9c877597170b929a6121a68dcd3dd9a80f45
+# Also in 6.1.150, 6.6.104, 6.12.y and 6.16.5 via the 2025-09-02 stable round.
+# The rose/hamradio subsystem was removed entirely in v7.1 (dd8d4bc28ad7).
+CVE_STATUS[CVE-2022-1247] = "fixed-version: Fixed from version 6.17"
-- 
2.43.0



  parent reply	other threads:[~2026-08-03  8:49 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03  8:48 [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 01/10] cve-exclusion: set status for CVE-2019-14899 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 02/10] cve-exclusion: set status for CVE-2021-3714 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 03/10] cve-exclusion: set status for CVE-2021-3864 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 04/10] cve-exclusion: set status for CVE-2022-0400 Junjie Cao
2026-08-03  8:48 ` Junjie Cao [this message]
2026-08-03  8:48 ` [OE-core][PATCH v2 06/10] cve-exclusion: set status for CVE-2022-4543 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 07/10] cve-exclusion: set status for CVE-2023-3397 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 08/10] cve-exclusion: set status for CVE-2023-4010 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 09/10] cve-exclusion: set status for CVE-2023-6238 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 10/10] cve-exclusion: set status for CVE-2023-6240 Junjie Cao
2026-08-06 11:52 ` [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Paul Barker
2026-08-10 10:19   ` Junjie Cao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260803084827.1348810-6-junjie.cao@linux.dev \
    --to=junjie.cao@linux.dev \
    --cc=Venkata.Navuduri@windriver.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=paul@pbarker.dev \
    --cc=randy.macleod@windriver.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.