Description
In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister(&idev->dev) put_device(&idev->dev) uio_device_release get_device(&idev->dev) kfree(idev) uio_free_minor(minor) uio_release put_device(&idev->dev) kfree(idev) ------------------------------------------------------- In the core-1 uio_unregister_device(), the device_unregister will kfree idev when the idev->dev kobject ref is 1. But after core-1 device_unregister, put_device and before doing kfree, the core-2 may get_device. Then: 1. After core-1 kfree idev, the core-2 will do use-after-free for idev. 2. When core-2 do uio_release and put_device, the idev will be double freed. To address this issue, we can get idev atomic & inc idev reference with minor_lock.
Details
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| linux | — | 5.15.0-102.112 |
| linux-allwinner-5.19 | — | — |
| linux-aws | — | 5.15.0-1057.63 |
| linux-aws-5.0 | — | — |
| linux-aws-5.11 | — | — |
| linux-aws-5.13 | — | — |
| linux-aws-5.15 | — | 5.15.0-1057.63~20.04.1 |
| linux-aws-5.19 | — | — |
| linux-aws-5.3 | — | — |
| linux-aws-5.4 | — | 5.4.0-1122.132~18.04.1 |
| linux-aws-5.8 | — | — |
| linux-aws-6.2 | — | — |
| linux-aws-6.5 | — | — |
| linux-aws-fips | — | 5.15.0-1057.63+fips1 |
| linux-aws-hwe | — | 4.15.0-1168.181~16.04.1 |
| linux-azure | — | 5.15.0-1060.69 |
| linux-azure-4.15 | — | 4.15.0-1177.192 |
| linux-azure-5.11 | — | — |
| linux-azure-5.13 | — | — |
| linux-azure-5.15 | — | 5.15.0-1060.69~20.04.1 |
| linux-azure-5.19 | — | — |
| linux-azure-5.3 | — | — |
| linux-azure-5.4 | — | 5.4.0-1127.134~18.04.1 |
| linux-azure-5.8 | — | — |
| linux-azure-6.2 | — | — |
| linux-azure-6.5 | — | — |
| linux-azure-edge | — | — |
| linux-azure-fde | — | — |
| linux-azure-fde-5.19 | — | — |
| linux-azure-fde-6.2 | — | — |
| linux-azure-fde-6.8 | — | — |
| linux-azure-fips | — | 5.15.0-1060.69+fips1 |
| linux-bluefield | — | — |
| linux-fips | — | 5.15.0-102.112+fips1 |
| linux-gcp | — | 5.15.0-1055.63 |
| linux-gcp-4.15 | — | 4.15.0-1162.179 |
| linux-gcp-5.11 | — | — |
| linux-gcp-5.13 | — | — |
| linux-gcp-5.15 | — | 5.15.0-1055.63~20.04.1 |
| linux-gcp-5.19 | — | — |
| linux-gcp-5.3 | — | — |
| linux-gcp-5.4 | — | 5.4.0-1126.135~18.04.1 |
| linux-gcp-5.8 | — | — |
| linux-gcp-6.2 | — | — |
| linux-gcp-6.5 | — | — |
| linux-gcp-fips | — | 5.15.0-1055.63+fips2 |
| linux-gke | — | 5.15.0-1054.59 |
| linux-gke-4.15 | — | — |
| linux-gke-5.15 | — | — |
| linux-gke-5.4 | — | — |
| linux-gkeop | — | 5.15.0-1040.46 |
| linux-gkeop-5.15 | — | 5.15.0-1040.46~20.04.1 |
| linux-gkeop-5.4 | — | — |
| linux-hwe | — | — |
| linux-hwe-5.11 | — | — |
| linux-hwe-5.13 | — | — |
| linux-hwe-5.15 | — | 5.15.0-102.112~20.04.1 |
| linux-hwe-5.19 | — | — |
| linux-hwe-5.4 | — | 5.4.0-175.195~18.04.1 |
| linux-hwe-5.8 | — | — |
| linux-hwe-6.2 | — | — |
| linux-hwe-6.5 | — | — |
| linux-hwe-edge | — | — |
| linux-ibm | — | 5.15.0-1050.53 |
| linux-ibm-5.15 | — | 5.15.0-1050.53~20.04.1 |
| linux-ibm-5.4 | — | 5.4.0-1069.74~18.04.1 |
| linux-intel-5.13 | — | — |
| linux-intel-iot-realtime | — | 5.15.0-1050.52 |
| linux-intel-iotg | — | 5.15.0-1052.58 |
| linux-intel-iotg-5.15 | — | 5.15.0-1052.58~20.04.1 |
| linux-iot | — | 5.4.0-1034.35 |
| linux-kvm | — | 5.15.0-1054.59 |
| linux-lowlatency | — | 5.15.0-102.112 |
| linux-lowlatency-hwe-5.15 | — | 5.15.0-102.112~20.04.1 |
| linux-lowlatency-hwe-5.19 | — | — |
| linux-lowlatency-hwe-6.2 | — | — |
| linux-lowlatency-hwe-6.5 | — | — |
| linux-nvidia | — | 5.15.0-1048.48 |
| linux-nvidia-6.2 | — | — |
| linux-nvidia-6.5 | — | 6.5.0-1014.14 |
| linux-nvidia-tegra | — | 5.15.0-1025.25 |
| linux-nvidia-tegra-5.15 | — | 5.15.0-1025.25~20.04.1 |
| linux-nvidia-tegra-igx | — | 5.15.0-1012.12 |
| linux-oem | — | — |
| linux-oem-5.10 | — | — |
| linux-oem-5.13 | — | — |
| linux-oem-5.14 | — | — |
| linux-oem-5.17 | — | — |
| linux-oem-5.6 | — | — |
| linux-oem-6.0 | — | — |
| linux-oem-6.1 | — | 6.1.0-1035.35 |
| linux-oem-6.5 | — | — |
| linux-oracle | — | 5.15.0-1055.61 |
| linux-oracle-5.0 | — | — |
| linux-oracle-5.11 | — | — |
| linux-oracle-5.13 | — | — |
| linux-oracle-5.15 | — | 5.15.0-1055.61~20.04.1 |
| linux-oracle-5.3 | — | — |
| linux-oracle-5.4 | — | 5.4.0-1121.130~18.04.1 |
| linux-oracle-5.8 | — | — |
| linux-oracle-6.5 | — | — |
| linux-raspi | — | 5.15.0-1050.53 |
| linux-raspi-5.4 | — | 5.4.0-1106.118~18.04.1 |
| linux-raspi-realtime | — | 6.8.0-2001.1 |
| linux-raspi2 | — | — |
| linux-realtime | — | 5.15.0-1058.66 |
| linux-riscv | — | — |
| linux-riscv-5.11 | — | — |
| linux-riscv-5.15 | — | 5.15.0-1053.57~20.04.1 |
| linux-riscv-5.19 | — | — |
| linux-riscv-5.8 | — | — |
| linux-riscv-6.5 | — | — |
| linux-starfive-5.19 | — | — |
| linux-starfive-6.2 | — | — |
| linux-starfive-6.5 | — | — |
| linux-xilinx-zynqmp | — | 5.15.0-1030.34 |
References
Similar Threats
- Unknown CGA-23jx-hhcx-m389
- Unknown CGA-2qp7-6757-fmgc
- Unknown CGA-2rj5-jc55-r267
- Unknown CGA-3m96-cwq8-6xmx
- Unknown CGA-3qj9-973w-fh9g
Exploit Protection
Help block exploit attempts
BotEraser is designed to detect and help reduce malicious bot traffic that may target known vulnerabilities on your site.
Try BotEraser Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.