All of lore.kernel.org
 help / color / mirror / Atom feed
From: Junjie Cao <junjie.cao@linux.dev>
To: openembedded-core@lists.openembedded.org
Cc: paul@pbarker.dev, randy.macleod@windriver.com,
	Venkata.Navuduri@windriver.com
Subject: [OE-core][PATCH v2 08/10] cve-exclusion: set status for CVE-2023-4010
Date: Mon,  3 Aug 2026 01:48:25 -0700	[thread overview]
Message-ID: <20260803084827.1348810-9-junjie.cao@linux.dev> (raw)
In-Reply-To: <20260803084827.1348810-1-junjie.cao@linux.dev>

The CVE text attributes a system lockup to usb_giveback_urb() in the USB
HCD framework. That function does not exist in the kernel; the closest
name is usb_giveback_urb_bh(). Ubuntu's security team noted the same
discrepancy when triaging the issue.

The reporter's proof of concept identifies the actual driver. Its
output shows the imon driver repeatedly printing errors and consuming
CPU:

  https://github.com/wanrenmi/a-usb-kernel-bug

usb_rx_callback_intf0() and usb_rx_callback_intf1() in
drivers/media/rc/imon.c resubmitted the RX URB after logging an error,
so a device returning -EPROTO caused an unbounded warning loop. That is
fixed by:

  https://git.kernel.org/linus/eecd203ada43a4693ce6fdd3a58ae10c7819252c
  ("media: imon: make send_packet() more robust", v6.18)

whose commit message describes the same mechanism: "usb_rx_callback_intf0()
resubmits urb after printk(), and resubmitted urb causes
usb_rx_callback_intf0() to again get -EPROTO error. This results in
printk() flooding (RCU stalls)". The fix returns early for those error
codes instead of resubmitting.

The impact is lower than the CVE suggests. It needs physical access to
attach a malicious device, and Ubuntu's triage concluded "There is no
system lockup happening", only unthrottled logging:

  https://ubuntu.com/security/CVE-2023-4010

Ubuntu's tracker data reaches the same conclusion about which driver is
at fault: it records "break-fix: 21677cfc562a -" for this CVE, and
21677cfc562a is "V4L/DVB: ir-core: add imon driver", the commit that
introduced the driver. Their note explains the choice: "The imon driver
has been issuing those warnings since its inception, so using that as
the break commit."

The tie to the fixing commit is an inference: eecd203ada43 carries no
CVE reference or Fixes tag, so no tracker links the two. It rests on the
reported function not existing, Ubuntu and the reporter's PoC both
pointing at imon, and the mechanism the commit fixes matching the
report.

CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
  list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
  of leaving them undocumented
- disclosed AI assistance per the contributor guide

v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/

 meta/recipes-kernel/linux/cve-exclusion.inc | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index 827a487e..0647586f 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -239,3 +239,8 @@ considered a defence against local attackers"
 # https://lore.kernel.org/all/20230515095956.17898-1-zyytlz.wz@163.com/
 CVE_STATUS[CVE-2023-3397] = "unpatched: no upstream fix, the only proposed \
 patch was withdrawn by its author and the affected fs/jfs code is unchanged"
+
+# Fix https://git.kernel.org/linus/eecd203ada43a4693ce6fdd3a58ae10c7819252c
+# The CVE names usb_giveback_urb(), which does not exist; the reporter's PoC
+# and Ubuntu's break-fix data both point at drivers/media/rc/imon.c.
+CVE_STATUS[CVE-2023-4010] = "fixed-version: Fixed from version 6.18"
-- 
2.43.0



  parent reply	other threads:[~2026-08-03  8:50 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03  8:48 [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 01/10] cve-exclusion: set status for CVE-2019-14899 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 02/10] cve-exclusion: set status for CVE-2021-3714 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 03/10] cve-exclusion: set status for CVE-2021-3864 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 04/10] cve-exclusion: set status for CVE-2022-0400 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 05/10] cve-exclusion: set status for CVE-2022-1247 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 06/10] cve-exclusion: set status for CVE-2022-4543 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 07/10] cve-exclusion: set status for CVE-2023-3397 Junjie Cao
2026-08-03  8:48 ` Junjie Cao [this message]
2026-08-03  8:48 ` [OE-core][PATCH v2 09/10] cve-exclusion: set status for CVE-2023-6238 Junjie Cao
2026-08-03  8:48 ` [OE-core][PATCH v2 10/10] cve-exclusion: set status for CVE-2023-6240 Junjie Cao
2026-08-06 11:52 ` [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Paul Barker
2026-08-10 10:19   ` Junjie Cao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260803084827.1348810-9-junjie.cao@linux.dev \
    --to=junjie.cao@linux.dev \
    --cc=Venkata.Navuduri@windriver.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=paul@pbarker.dev \
    --cc=randy.macleod@windriver.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.