• 公告ID (KylinSec-SA-2024-2911)

摘要:

In the Linux kernel, the following vulnerability has been resolved:

RDMA: Fix use-after-free in rxe_queue_cleanup

On error handling path in rxe_qp_from_init() qp->sq.queue is freed and
then rxe_create_qp() will drop last reference to this object. qp clean up
function will try to free this queue one time and it causes UAF bug.

Fix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().

安全等级: Low

公告ID: KylinSec-SA-2024-2911

发布日期: 2024年6月27日

关联CVE: CVE-2021-47616  

  • 详细介绍

1. 漏洞描述

   

In the Linux kernel, the following vulnerability has been resolved:

RDMA: Fix use-after-free in rxe_queue_cleanup

On error handling path in rxe_qp_from_init() qp->sq.queue is freed and
then rxe_create_qp() will drop last reference to this object. qp clean up
function will try to free this queue one time and it causes UAF bug.

Fix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-47616 KY3.4-5A kernel Unaffected
CVE-2021-47616 KY3.5.2 kernel Unaffected
CVE-2021-47616 V6 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-2910 下一篇:KylinSec-SA-2024-2912