Alexander Coffin
49c742afd6
wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()
[ Upstream commit 3f42faf6db431e04bf942d2ebe3ae88975723478 ]
> ret = brcmf_proto_tx_queue_data(drvr, ifp->ifidx, skb);
may be schedule, and then complete before the line
> ndev->stats.tx_bytes += skb->len;
[ 46.912801] ==================================================================
[ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac]
[ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328
[ 46.935991]
[ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1
[ 46.947255] Hardware name: [REDACTED]
[ 46.954568] Call trace:
[ 46.957037] dump_backtrace+0x0/0x2b8
[ 46.960719] show_stack+0x24/0x30
[ 46.964052] dump_stack+0x128/0x194
[ 46.967557] print_address_description.isra.0+0x64/0x380
[ 46.972877] __kasan_report+0x1d4/0x240
[ 46.976723] kasan_report+0xc/0x18
[ 46.980138] __asan_report_load4_noabort+0x18/0x20
[ 46.985027] brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac]
[ 46.990613] dev_hard_start_xmit+0x1bc/0xda0
[ 46.994894] sch_direct_xmit+0x198/0xd08
[ 46.998827] __qdisc_run+0x37c/0x1dc0
[ 47.002500] __dev_queue_xmit+0x1528/0x21f8
[ 47.006692] dev_queue_xmit+0x24/0x30
[ 47.010366] neigh_resolve_output+0x37c/0x678
[ 47.014734] ip_finish_output2+0x598/0x2458
[ 47.018927] __ip_finish_output+0x300/0x730
[ 47.023118] ip_output+0x2e0/0x430
[ 47.026530] ip_local_out+0x90/0x140
[ 47.030117] igmpv3_sendpack+0x14c/0x228
[ 47.034049] igmpv3_send_cr+0x384/0x6b8
[ 47.037895] igmp_ifc_timer_expire+0x4c/0x118
[ 47.042262] call_timer_fn+0x1cc/0xbe8
[ 47.046021] __run_timers+0x4d8/0xb28
[ 47.049693] run_timer_softirq+0x24/0x40
[ 47.053626] __do_softirq+0x2c0/0x117c
[ 47.057387] irq_exit+0x2dc/0x388
[ 47.060715] __handle_domain_irq+0xb4/0x158
[ 47.064908] gic_handle_irq+0x58/0xb0
[ 47.068581] el0_irq_naked+0x50/0x5c
[ 47.072162]
[ 47.073665] Allocated by task 328:
[ 47.077083] save_stack+0x24/0xb0
[ 47.080410] __kasan_kmalloc.isra.0+0xc0/0xe0
[ 47.084776] kasan_slab_alloc+0x14/0x20
[ 47.088622] kmem_cache_alloc+0x15c/0x468
[ 47.092643] __alloc_skb+0xa4/0x498
[ 47.096142] igmpv3_newpack+0x158/0xd78
[ 47.099987] add_grhead+0x210/0x288
[ 47.103485] add_grec+0x6b0/0xb70
[ 47.106811] igmpv3_send_cr+0x2e0/0x6b8
[ 47.110657] igmp_ifc_timer_expire+0x4c/0x118
[ 47.115027] call_timer_fn+0x1cc/0xbe8
[ 47.118785] __run_timers+0x4d8/0xb28
[ 47.122457] run_timer_softirq+0x24/0x40
[ 47.126389] __do_softirq+0x2c0/0x117c
[ 47.130142]
[ 47.131643] Freed by task 180:
[ 47.134712] save_stack+0x24/0xb0
[ 47.138041] __kasan_slab_free+0x108/0x180
[ 47.142146] kasan_slab_free+0x10/0x18
[ 47.145904] slab_free_freelist_hook+0xa4/0x1b0
[ 47.150444] kmem_cache_free+0x8c/0x528
[ 47.154292] kfree_skbmem+0x94/0x108
[ 47.157880] consume_skb+0x10c/0x5a8
[ 47.161466] __dev_kfree_skb_any+0x88/0xa0
[ 47.165598] brcmu_pkt_buf_free_skb+0x44/0x68 [brcmutil]
[ 47.171023] brcmf_txfinalize+0xec/0x190 [brcmfmac]
[ 47.176016] brcmf_proto_bcdc_txcomplete+0x1c0/0x210 [brcmfmac]
[ 47.182056] brcmf_sdio_sendfromq+0x8dc/0x1e80 [brcmfmac]
[ 47.187568] brcmf_sdio_dpc+0xb48/0x2108 [brcmfmac]
[ 47.192529] brcmf_sdio_dataworker+0xc8/0x238 [brcmfmac]
[ 47.197859] process_one_work+0x7fc/0x1a80
[ 47.201965] worker_thread+0x31c/0xc40
[ 47.205726] kthread+0x2d8/0x370
[ 47.208967] ret_from_fork+0x10/0x18
[ 47.212546]
[ 47.214051] The buggy address belongs to the object at ffffff803f588280
[ 47.214051] which belongs to the cache skbuff_head_cache of size 208
[ 47.227086] The buggy address is located 104 bytes inside of
[ 47.227086] 208-byte region [ffffff803f588280, ffffff803f588350)
[ 47.238814] The buggy address belongs to the page:
[ 47.243618] page:ffffffff00dd6200 refcount:1 mapcount:0 mapping:ffffff804b6bf800 index:0xffffff803f589900 compound_mapcount: 0
[ 47.255007] flags: 0x10200(slab|head)
[ 47.258689] raw: 0000000000010200 ffffffff00dfa980 0000000200000002 ffffff804b6bf800
[ 47.266439] raw: ffffff803f589900 0000000080190018 00000001ffffffff 0000000000000000
[ 47.274180] page dumped because: kasan: bad access detected
[ 47.279752]
[ 47.281251] Memory state around the buggy address:
[ 47.286051] ffffff803f588180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 47.293277] ffffff803f588200: fb fb fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 47.300502] >ffffff803f588280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 47.307723] ^
[ 47.314343] ffffff803f588300: fb fb fb fb fb fb fb fb fb fb fc fc fc fc fc fc
[ 47.321569] ffffff803f588380: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb
[ 47.328789] ==================================================================
Signed-off-by: Alexander Coffin <alex.coffin@matician.com>
Signed-off-by: Kalle Valo <kvalo@kernel.org>
Link: https://lore.kernel.org/r/20220808174925.3922558-1-alex.coffin@matician.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2022-10-26 13:22:49 +02:00 |
| .. |
|
accessibility
|
|
|
|
acpi
|
ACPI: video: Add Toshiba Satellite/Portege Z830 quirk
|
2022-10-26 13:22:47 +02:00 |
|
amba
|
|
|
|
android
|
binder: fix UAF of ref->proc caused by race condition
|
2022-09-15 12:04:51 +02:00 |
|
ata
|
libata: add ATA_HORKAGE_NOLPM for Pioneer BDR-207M and BDR-205
|
2022-10-05 10:37:42 +02:00 |
|
atm
|
atm: idt77252: fix use-after-free bugs caused by tst_timer
|
2022-08-25 11:18:26 +02:00 |
|
auxdisplay
|
|
|
|
base
|
x86/bugs: Report AMD retbleed vulnerability
|
2022-10-07 09:16:54 +02:00 |
|
bcma
|
|
|
|
block
|
loop: Check for overflow while configuring loop
|
2022-09-05 10:27:43 +02:00 |
|
bluetooth
|
Bluetooth: hci_intel: Add check for platform_driver_register
|
2022-08-25 11:17:47 +02:00 |
|
bus
|
bus: hisi_lpc: fix missing platform_device_put() in hisi_lpc_acpi_probe()
|
2022-08-25 11:17:35 +02:00 |
|
cdrom
|
|
|
|
char
|
random: use expired timer rather than wq for mixing fast pool
|
2022-10-15 07:54:40 +02:00 |
|
clk
|
clk: ast2600: BCLK comes from EPLL
|
2022-10-26 13:22:43 +02:00 |
|
clocksource
|
clocksource/drivers/ixp4xx: remove EXPORT_SYMBOL_GPL from ixp4xx_timer_setup()
|
2022-07-07 17:36:53 +02:00 |
|
connector
|
|
|
|
counter
|
|
|
|
cpufreq
|
x86/devicetable: Move x86 specific macro out of generic code
|
2022-10-07 09:16:54 +02:00 |
|
cpuidle
|
|
|
|
crypto
|
crypto: cavium - prevent integer overflow loading firmware
|
2022-10-26 13:22:46 +02:00 |
|
dax
|
|
|
|
dca
|
|
|
|
devfreq
|
PM / devfreq: exynos-ppmu: Fix refcount leak in of_get_devfreq_events
|
2022-07-07 17:36:49 +02:00 |
|
dio
|
|
|
|
dma
|
dmaengine: ioat: stop mod_timer from resurrecting deleted timer in __cleanup()
|
2022-10-26 13:22:43 +02:00 |
|
dma-buf
|
udmabuf: Set the DMA mask for the udmabuf device (v2)
|
2022-09-05 10:27:45 +02:00 |
|
edac
|
|
|
|
eisa
|
|
|
|
extcon
|
extcon: Modify extcon device to be created after driver data is set
|
2022-06-14 18:12:00 +02:00 |
|
firewire
|
firewire: core: extend card->lock in fw_core_handle_bus_reset
|
2022-05-12 12:23:41 +02:00 |
|
firmware
|
firmware: google: Test spinlock on panic path to avoid lockups
|
2022-10-26 13:22:40 +02:00 |
|
fpga
|
fpga: altera-pr-ip: fix unsigned comparison with less than zero
|
2022-08-25 11:17:51 +02:00 |
|
fsi
|
fsi: core: Check error number after calling ida_simple_get
|
2022-10-26 13:22:41 +02:00 |
|
gnss
|
|
|
|
gpio
|
gpio: mpc8xxx: Fix support for IRQ_TYPE_LEVEL_LOW flow_type in mpc85xx
|
2022-09-28 11:03:57 +02:00 |
|
gpu
|
drm/msm/dpu: index dpu_kms->hw_vbif using vbif_idx
|
2022-10-26 13:22:30 +02:00 |
|
greybus
|
|
|
|
hid
|
HID: multitouch: Add memory barriers
|
2022-10-26 13:22:14 +02:00 |
|
hsi
|
HSI: omap_ssi_port: Fix dma_map_sg error check
|
2022-10-26 13:22:36 +02:00 |
|
hv
|
Drivers: hv: Never allocate anything besides framebuffer from framebuffer memory region
|
2022-09-28 11:04:08 +02:00 |
|
hwmon
|
hwmon: (gpio-fan) Fix array out of bounds access
|
2022-09-15 12:04:52 +02:00 |
|
hwspinlock
|
|
|
|
hwtracing
|
intel_th: pci: Add Meteor Lake-P support
|
2022-08-25 11:18:13 +02:00 |
|
i2c
|
i2c: mux-gpmux: Add of_node_put() when breaking out of loop
|
2022-08-25 11:17:47 +02:00 |
|
i3c
|
|
|
|
ide
|
|
|
|
idle
|
intel_idle: Disable IBRS during long idle
|
2022-10-07 09:16:55 +02:00 |
|
iio
|
iio: inkern: only release the device node when done with it
|
2022-10-26 13:22:34 +02:00 |
|
infiniband
|
RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.
|
2022-10-26 13:22:38 +02:00 |
|
input
|
Input: xpad - fix wireless 360 controller breaking after suspend
|
2022-10-15 07:54:41 +02:00 |
|
interconnect
|
|
|
|
iommu
|
iommu/omap: Fix buffer overflow in debugfs
|
2022-10-26 13:22:45 +02:00 |
|
ipack
|
|
|
|
irqchip
|
irqchip/tegra: Fix overflow implicit truncation warnings
|
2022-08-25 11:18:32 +02:00 |
|
isdn
|
mISDN: fix use-after-free bugs in l1oip timer handlers
|
2022-10-26 13:22:25 +02:00 |
|
leds
|
|
|
|
lightnvm
|
|
|
|
macintosh
|
macintosh/adb: fix oob read in do_adb_query() function
|
2022-08-11 12:57:53 +02:00 |
|
mailbox
|
mailbox: bcm-ferxrm-mailbox: Fix error check for dma_map_sg
|
2022-10-26 13:22:44 +02:00 |
|
mcb
|
|
|
|
md
|
md/raid5: Ensure stripe_fill happens on non-read IO with journal
|
2022-10-26 13:22:39 +02:00 |
|
media
|
media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init
|
2022-10-26 13:22:36 +02:00 |
|
memory
|
memory: of: Fix refcount leak bug in of_get_ddr_timings()
|
2022-10-26 13:22:31 +02:00 |
|
memstick
|
memstick/ms_block: Fix a memory leak
|
2022-08-25 11:17:55 +02:00 |
|
message
|
|
|
|
mfd
|
mfd: sm501: Add check for platform_driver_register()
|
2022-10-26 13:22:42 +02:00 |
|
misc
|
misc: ocxl: fix possible refcount leak in afu_ioctl()
|
2022-10-26 13:22:37 +02:00 |
|
mmc
|
mmc: wmt-sdmmc: Fix an error handling path in wmt_mci_probe()
|
2022-10-26 13:22:30 +02:00 |
|
mtd
|
mtd: rawnand: meson: fix bit map use in meson_nfc_ecc_correct()
|
2022-10-26 13:22:39 +02:00 |
|
mux
|
|
|
|
net
|
wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()
|
2022-10-26 13:22:49 +02:00 |
|
nfc
|
NFC: nxp-nci: don't print header length mismatch on i2c error
|
2022-07-21 20:59:25 +02:00 |
|
ntb
|
NTB: ntb_tool: uninitialized heap data in tool_fn_write()
|
2022-08-25 11:18:26 +02:00 |
|
nubus
|
|
|
|
nvdimm
|
nvdimm: Fix badblocks clear off-by-one error
|
2022-07-07 17:36:48 +02:00 |
|
nvme
|
nvme: Fix IOC_PR_CLEAR and IOC_PR_RELEASE ioctls for nvme devices
|
2022-10-05 10:37:45 +02:00 |
|
nvmem
|
|
|
|
of
|
of: mdio: Add of_node_put() when breaking out of for_each_xx
|
2022-09-28 11:04:06 +02:00 |
|
opp
|
opp: Fix error check in dev_pm_opp_attach_genpd()
|
2022-08-25 11:18:00 +02:00 |
|
oprofile
|
|
|
|
parisc
|
parisc: ccio-dma: Add missing iounmap in error path in ccio_probe()
|
2022-09-28 11:03:57 +02:00 |
|
parport
|
|
|
|
pci
|
PCI: Sanitise firmware BAR assignments behind a PCI-PCI bridge
|
2022-10-26 13:22:16 +02:00 |
|
pcmcia
|
pcmcia: db1xxx_ss: restrict to MIPS_DB1XXX boards
|
2022-06-14 18:11:50 +02:00 |
|
perf
|
perf/arm_pmu_platform: fix tests for platform_get_irq() failure
|
2022-09-20 12:27:59 +02:00 |
|
phy
|
phy: qualcomm: call clk_disable_unprepare in the error handling
|
2022-10-26 13:22:40 +02:00 |
|
pinctrl
|
pinctrl: amd: Don't save/restore interrupt status and wake status bits
|
2022-09-05 10:27:39 +02:00 |
|
platform
|
platform/x86: msi-laptop: Fix resource cleanup
|
2022-10-26 13:22:28 +02:00 |
|
pnp
|
|
|
|
power
|
power/reset: arm-versatile: Fix refcount leak in versatile_reboot_probe
|
2022-07-29 17:14:10 +02:00 |
|
powercap
|
powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue
|
2022-10-26 13:22:47 +02:00 |
|
pps
|
|
|
|
ps3
|
|
|
|
ptp
|
|
|
|
pwm
|
pwm: lp3943: Fix duty calculation in case period was clamped
|
2022-06-14 18:11:51 +02:00 |
|
rapidio
|
|
|
|
ras
|
|
|
|
regulator
|
regulator: qcom_rpm: Fix circular deferral regression
|
2022-10-26 13:22:15 +02:00 |
|
remoteproc
|
remoteproc: qcom: wcnss: Fix handling of IRQs
|
2022-08-25 11:18:02 +02:00 |
|
reset
|
|
|
|
rpmsg
|
rpmsg: qcom: glink: replace strncpy() with strscpy_pad()
|
2022-10-15 07:54:38 +02:00 |
|
rtc
|
rtc: mt6397: check return value after calling platform_get_resource()
|
2022-06-14 18:11:53 +02:00 |
|
s390
|
s390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup
|
2022-09-28 11:04:08 +02:00 |
|
sbus
|
|
|
|
scsi
|
scsi: libsas: Fix use-after-free bug in smp_execute_task_sg()
|
2022-10-26 13:22:41 +02:00 |
|
sfi
|
|
|
|
sh
|
|
|
|
siox
|
|
|
|
slimbus
|
slimbus: qcom: Fix IRQ check in qcom_slim_probe
|
2022-05-18 09:47:27 +02:00 |
|
soc
|
soc: qcom: smem_state: Add refcounting for the 'state->of_node'
|
2022-10-26 13:22:32 +02:00 |
|
soundwire
|
soundwire: bus_type: fix remove and shutdown support
|
2022-08-25 11:17:54 +02:00 |
|
spi
|
spi: s3c64xx: Fix large transfers with DMA
|
2022-10-26 13:22:25 +02:00 |
|
spmi
|
spmi: pmic-arb: correct duplicate APID to PPID mapping logic
|
2022-10-26 13:22:43 +02:00 |
|
ssb
|
|
|
|
staging
|
staging: vt6655: fix some erroneous memory clean-up loops
|
2022-10-26 13:22:40 +02:00 |
|
target
|
|
|
|
tc
|
|
|
|
tee
|
tee: add overflow check in register_shm_helper()
|
2022-08-25 11:18:27 +02:00 |
|
thermal
|
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
|
2022-10-26 13:22:47 +02:00 |
|
thunderbolt
|
thunderbolt: Use the actual buffer in tb_async_error()
|
2022-09-15 12:04:52 +02:00 |
|
tty
|
serial: 8250: Fix restoring termios speed after suspend
|
2022-10-26 13:22:41 +02:00 |
|
uio
|
|
|
|
usb
|
usb: gadget: function: fix dangling pnp_string in f_printer.c
|
2022-10-26 13:22:39 +02:00 |
|
vfio
|
vfio: Clear the caps->buf to NULL after free
|
2022-08-25 11:18:36 +02:00 |
|
vhost
|
vhost/vsock: Use kvmalloc/kvfree for larger packets.
|
2022-10-26 13:22:25 +02:00 |
|
video
|
fbdev: smscufx: Fix use-after-free in ufx_ops_open()
|
2022-10-26 13:22:16 +02:00 |
|
virt
|
vboxguest: Do not use devm for irq
|
2022-08-25 11:18:33 +02:00 |
|
virtio
|
virtio_mmio: Restore guest page size on resume
|
2022-07-21 20:59:24 +02:00 |
|
visorbus
|
|
|
|
vlynq
|
|
|
|
vme
|
|
|
|
w1
|
|
|
|
watchdog
|
watchdog: armada_37xx_wdt: check the return value of devm_ioremap() in armada_37xx_wdt_probe()
|
2022-08-25 11:18:06 +02:00 |
|
xen
|
xen/xenbus: fix return type in xenbus_file_read()
|
2022-08-25 11:18:26 +02:00 |
|
zorro
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|