public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
       [not found] <2024073038-CVE-2024-42226-fa39@gregkh>
@ 2024-08-05  7:01 ` Jinjiang Tu
  2024-08-06  9:25   ` Jinjiang Tu
  0 siblings, 1 reply; 6+ messages in thread
From: Jinjiang Tu @ 2024-08-05  7:01 UTC (permalink / raw)
  To: gregkh; +Cc: cve, linux-cve-announce, linux-kernel

Hi,

I noticed the fix commit is reverted in 6.1.99 and 6.6.39 due to 
performance regression. Does it
means this CVE should be rejected?

Thanks!

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
  2024-08-05  7:01 ` CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB Jinjiang Tu
@ 2024-08-06  9:25   ` Jinjiang Tu
  2024-08-06 11:15     ` Neronin, Niklas
  0 siblings, 1 reply; 6+ messages in thread
From: Jinjiang Tu @ 2024-08-06  9:25 UTC (permalink / raw)
  To: niklas.neronin; +Cc: cve, gregkh, linux-cve-announce, linux-kernel, tujinjiang

Hi, Niklas

The commit 66cb618bf0bb ("usb: xhci: prevent potential failure in 
handle_tx_event() for Transfer events without TRB")
has been assigned with CVE-2024-42226, but the commit has been reverted 
in 6.1.99 and 6.6.39 due to
performance regression. Do you have a plan to address this issue, or if 
this CVE should be rejected?

Thanks!


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
  2024-08-06  9:25   ` Jinjiang Tu
@ 2024-08-06 11:15     ` Neronin, Niklas
  2024-08-06 13:53       ` Jinjiang Tu
  0 siblings, 1 reply; 6+ messages in thread
From: Neronin, Niklas @ 2024-08-06 11:15 UTC (permalink / raw)
  To: Jinjiang Tu; +Cc: cve, gregkh, linux-cve-announce, linux-kernel, Mathias Nyman

On 06/08/2024 12.25, Jinjiang Tu wrote:
> Hi, Niklas
> 
> The commit 66cb618bf0bb ("usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB")
> has been assigned with CVE-2024-42226, but the commit has been reverted in 6.1.99 and 6.6.39 due to
> performance regression. Do you have a plan to address this issue, or if this CVE should be rejected?
> 
> Thanks!
> 

Hi,

Currently, I have no plan to address this issue.

The commit in question, was not intended for any previous Linux versions.
It was created as part of my handle_tx_event() rework series. Future changes
in said series could potentially trigger the issue, so preemptively preventing
it was both simpler and more secure.

Thanks,
Niklas

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
  2024-08-06 11:15     ` Neronin, Niklas
@ 2024-08-06 13:53       ` Jinjiang Tu
  2024-08-07  9:31         ` Neronin, Niklas
  0 siblings, 1 reply; 6+ messages in thread
From: Jinjiang Tu @ 2024-08-06 13:53 UTC (permalink / raw)
  To: Neronin, Niklas
  Cc: cve, gregkh, linux-cve-announce, linux-kernel, Mathias Nyman


在 2024/8/6 19:15, Neronin, Niklas 写道:
> On 06/08/2024 12.25, Jinjiang Tu wrote:
>> Hi, Niklas
>>
>> The commit 66cb618bf0bb ("usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB")
>> has been assigned with CVE-2024-42226, but the commit has been reverted in 6.1.99 and 6.6.39 due to
>> performance regression. Do you have a plan to address this issue, or if this CVE should be rejected?
>>
>> Thanks!
>>
> Hi,
>
> Currently, I have no plan to address this issue.
>
> The commit in question, was not intended for any previous Linux versions.
> It was created as part of my handle_tx_event() rework series. Future changes
> in said series could potentially trigger the issue, so preemptively preventing
> it was both simpler and more secure.
I don't know if I'm understanding this right, do you mean the issue 
mentioned in
the commit will not be actually triggered in previous Linux versions? 
Now the commit
is reverted in v6.1 and v6.6, but the issue can not be triggered in 
these versions,
so no more fixes patch is needed for these LTS versions?

Thanks!

>
> Thanks,
> Niklas
>

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
  2024-08-06 13:53       ` Jinjiang Tu
@ 2024-08-07  9:31         ` Neronin, Niklas
  2024-08-11 15:33           ` Greg KH
  0 siblings, 1 reply; 6+ messages in thread
From: Neronin, Niklas @ 2024-08-07  9:31 UTC (permalink / raw)
  To: Jinjiang Tu; +Cc: cve, gregkh, linux-cve-announce, linux-kernel, Mathias Nyman



On 06/08/2024 16.53, Jinjiang Tu wrote:
> 
> 在 2024/8/6 19:15, Neronin, Niklas 写道:
>> On 06/08/2024 12.25, Jinjiang Tu wrote:
>>> Hi, Niklas
>>>
>>> The commit 66cb618bf0bb ("usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB")
>>> has been assigned with CVE-2024-42226, but the commit has been reverted in 6.1.99 and 6.6.39 due to
>>> performance regression. Do you have a plan to address this issue, or if this CVE should be rejected?
>>>
>>> Thanks!
>>>
>> Hi,
>>
>> Currently, I have no plan to address this issue.
>>
>> The commit in question, was not intended for any previous Linux versions.
>> It was created as part of my handle_tx_event() rework series. Future changes
>> in said series could potentially trigger the issue, so preemptively preventing
>> it was both simpler and more secure.
> I don't know if I'm understanding this right, do you mean the issue mentioned in
> the commit will not be actually triggered in previous Linux versions? Now the commit
> is reverted in v6.1 and v6.6, but the issue can not be triggered in these versions,
> so no more fixes patch is needed for these LTS versions?

I'm not aware of any cases where this issue has been triggered. As it has been in the
Linux kernel for a long time, I assume it does not trigger.

Thanks,
Niklas



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
  2024-08-07  9:31         ` Neronin, Niklas
@ 2024-08-11 15:33           ` Greg KH
  0 siblings, 0 replies; 6+ messages in thread
From: Greg KH @ 2024-08-11 15:33 UTC (permalink / raw)
  To: Neronin, Niklas
  Cc: Jinjiang Tu, cve, linux-cve-announce, linux-kernel, Mathias Nyman

On Wed, Aug 07, 2024 at 12:31:56PM +0300, Neronin, Niklas wrote:
> 
> 
> On 06/08/2024 16.53, Jinjiang Tu wrote:
> > 
> > 在 2024/8/6 19:15, Neronin, Niklas 写道:
> >> On 06/08/2024 12.25, Jinjiang Tu wrote:
> >>> Hi, Niklas
> >>>
> >>> The commit 66cb618bf0bb ("usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB")
> >>> has been assigned with CVE-2024-42226, but the commit has been reverted in 6.1.99 and 6.6.39 due to
> >>> performance regression. Do you have a plan to address this issue, or if this CVE should be rejected?
> >>>
> >>> Thanks!
> >>>
> >> Hi,
> >>
> >> Currently, I have no plan to address this issue.
> >>
> >> The commit in question, was not intended for any previous Linux versions.
> >> It was created as part of my handle_tx_event() rework series. Future changes
> >> in said series could potentially trigger the issue, so preemptively preventing
> >> it was both simpler and more secure.
> > I don't know if I'm understanding this right, do you mean the issue mentioned in
> > the commit will not be actually triggered in previous Linux versions? Now the commit
> > is reverted in v6.1 and v6.6, but the issue can not be triggered in these versions,
> > so no more fixes patch is needed for these LTS versions?
> 
> I'm not aware of any cases where this issue has been triggered. As it has been in the
> Linux kernel for a long time, I assume it does not trigger.

Ok, now rejected, thanks.

greg k-h

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-08-11 15:33 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <2024073038-CVE-2024-42226-fa39@gregkh>
2024-08-05  7:01 ` CVE-2024-42226: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB Jinjiang Tu
2024-08-06  9:25   ` Jinjiang Tu
2024-08-06 11:15     ` Neronin, Niklas
2024-08-06 13:53       ` Jinjiang Tu
2024-08-07  9:31         ` Neronin, Niklas
2024-08-11 15:33           ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox