No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Pedro Tammela dbe778b08b net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
[ Upstream commit 2e95c4384438adeaa772caa560244b1a2efef816 ]

In qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed
to be either root or ingress. This assumption is bogus since it's valid
to create egress qdiscs with major handle ffff:
Budimir Markovic found that for qdiscs like DRR that maintain an active
class list, it will cause a UAF with a dangling class pointer.

In 066a3b5b23, the concern was to avoid iterating over the ingress
qdisc since its parent is itself. The proper fix is to stop when parent
TC_H_ROOT is reached because the only way to retrieve ingress is when a
hierarchy which does not contain a ffff: major handle call into
qdisc_lookup with TC_H_MAJ(TC_H_ROOT).

In the scenario where major ffff: is an egress qdisc in any of the tree
levels, the updates will also propagate to TC_H_ROOT, which then the
iteration must stop.

Fixes: 066a3b5b23 ("[NET_SCHED] sch_api: fix qdisc_tree_decrease_qlen() loop")
Reported-by: Budimir Markovic <markovicbudimir@gmail.com>
Suggested-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>

 net/sched/sch_api.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Reviewed-by: Simon Horman <horms@kernel.org>

Link: https://patch.msgid.link/20241024165547.418570-1-jhs@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-08 16:20:52 +01:00
arch arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning 2024-11-08 16:20:52 +01:00
block blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race 2024-11-08 16:20:48 +01:00
certs
crypto crypto: aead,cipher - zeroize key buffer after use 2024-11-08 16:20:33 +01:00
Documentation dt-bindings: gpu: Convert Samsung Image Rotator to dt-schema 2024-11-08 16:20:52 +01:00
drivers gtp: allow -1 to be specified as file description from userspace 2024-11-08 16:20:52 +01:00
fs nilfs2: fix kernel bug due to missing clearing of buffer delay flag 2024-11-08 16:20:51 +01:00
include mac80211: Add support to trigger sta disconnect on hardware restart 2024-11-08 16:20:52 +01:00
init init: open /initrd.image with O_LARGEFILE 2024-04-13 12:51:36 +02:00
ipc ipc: replace costly bailout check in sysvipc_find_ipc() 2024-09-04 13:15:02 +02:00
kernel cgroup: Fix potential overflow issue when checking max_depth 2024-11-08 16:20:52 +01:00
lib debugobjects: Fix conditions in fill_pool() 2024-11-08 16:20:34 +01:00
LICENSES
mm mm/swapfile: skip HugeTLB pages for unuse_vma 2024-11-08 16:20:47 +01:00
net net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT 2024-11-08 16:20:52 +01:00
samples media: rename VFL_TYPE_GRABBER to _VIDEO 2024-03-26 18:22:22 -04:00
scripts scripts: kconfig: merge_config: config files: add a trailing newline 2024-11-08 16:20:24 +01:00
security selinux: improve error checking in sel_write_load() 2024-11-08 16:20:52 +01:00
sound ASoC: cs42l51: Fix some error handling paths in cs42l51_probe() 2024-11-08 16:20:52 +01:00
tools tools/iio: Add memory allocation failure check for trigger_name 2024-11-08 16:20:45 +01:00
usr
virt KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin() 2024-11-08 16:20:47 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore Remove *.orig pattern from .gitignore 2024-11-08 16:20:33 +01:00
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS iio: stx104: Move to addac subdirectory 2023-08-30 16:27:12 +02:00
Makefile Linux 5.4.284 2024-09-12 11:03:57 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.