android_kernel_motorola_sm6375/net/can
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Oliver Hartkopp 19f553a1dd can: bcm: add missing rcu read protection for procfs content
commit dac5e6249159ac255dad9781793dbe5908ac9ddb upstream.

When the procfs content is generated for a bcm_op which is in the process
to be removed the procfs output might show unreliable data (UAF).

As the removal of bcm_op's is already implemented with rcu handling this
patch adds the missing rcu_read_lock() and makes sure the list entries
are properly removed under rcu protection.

Fixes: f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly synchronize_rcu()")
Reported-by: Anderson Nascimento <anderson@allelesecurity.com>
Suggested-by: Anderson Nascimento <anderson@allelesecurity.com>
Tested-by: Anderson Nascimento <anderson@allelesecurity.com>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Link: https://patch.msgid.link/20250519125027.11900-2-socketcan@hartkopp.net
Cc: stable@vger.kernel.org # >= 5.4
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-04 14:32:35 +02:00
..
j1939 can: j1939: j1939_sk_send_loop(): fix unable to send messages with data length zero 2025-03-13 12:43:16 +01:00
af_can.c can: statistics: use atomic access in hot path 2025-04-10 14:29:42 +02:00
af_can.h can: statistics: use atomic access in hot path 2025-04-10 14:29:42 +02:00
bcm.c can: bcm: add missing rcu read protection for procfs content 2025-06-04 14:32:35 +02:00
gw.c
Kconfig
Makefile
proc.c can: statistics: use atomic access in hot path 2025-04-10 14:29:42 +02:00
raw.c can: raw: add support for SO_MARK 2024-01-15 18:25:25 +01:00