In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt handler to dereference freed memory, leading to a use-after-free or NULL pointer dereference in mana_hwc_handle_resp(). mana_smc_teardown_hwc() signals the hardware to stop but does not synchronize against IRQ handlers already executing on other CPUs. The IRQ synchronization only happens in mana_hwc_destroy_cq() via mana_gd_destroy_eq() -> mana_gd_deregister_irq(). Since this runs after kfree(hwc->caller_ctx), a concurrent mana_hwc_rx_event_handler() can dereference freed caller_ctx (and rxq->msg_buf) in mana_hwc_handle_resp(). Fix this by reordering teardown to reverse-of-creation order: destroy the TX/RX work queues and CQ/EQ before freeing hwc->caller_ctx. This ensures all in-flight interrupt handlers complete before the memory they access is freed.
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: mana: corrige uso después de liberación en mana_hwc_destroy_channel() reordenando el desmantelamiento Existe una potencial condición de carrera en mana_hwc_destroy_channel() donde hwc -> caller_ctx es liberado antes de que la Cola de Completado (CQ) y la Cola de Eventos (EQ) del HWC sean destruidas. Esto permite a un gestor de interrupciones de CQ en curso desreferenciar memoria liberada, lo que lleva a un uso después de liberación o a una desreferencia de puntero NULL en mana_hwc_handle_resp(). mana_smc_teardown_hwc() le indica al hardware que se detenga pero no se sincroniza con los gestores de IRQ que ya se están ejecutando en otras CPUs. La sincronización de IRQ solo ocurre en mana_hwc_destroy_cq() a través de mana_gd_destroy_eq() -> mana_gd_deregister_irq(). Dado que esto se ejecuta después de kfree(hwc -> caller_ctx), un mana_hwc_rx_event_handler() concurrente puede desreferenciar caller_ctx liberado (y rxq -> msg_buf) en mana_hwc_handle_resp(). Solucione esto reordenando el desmantelamiento al orden inverso de creación: destruya las colas de trabajo TX/RX y CQ/EQ antes de liberar hwc -> caller_ctx. Esto asegura que todos los gestores de interrupciones en curso se completen antes de que la memoria a la que acceden sea liberada.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-416
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242455f440> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24245378c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424536980> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242455ed40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242455ce00> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242455f400> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23bea8b500> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d242455f280> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d242a72bfc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d242455e180> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |