Beschreibung
In the Linux kernel, the following vulnerability has been resolved: net: shaper: rework the VALID marking (again) Recent commit changed the semantics from NOT_VALID to VALID. I didn-t realize that the flags are not stored atomically with the entry in XArray. There-s still a race of reader observing a VALID mark for a slot, getting interrupted, writer replacing the entry with a different one, reader continuing, fetching the entry which is now a different pointer than the pointer for which VALID was meant. The biggest consequence of this is that we may see a UAF since net_shaper_rollback() assumed that entries without VALID can be freed without observing RCU. Looks like the XArray marks are buying us nothing at this point. Let-s convert the code to an explicit valid field. The smp_load_acquire() / smp_store_release() barriers are marginally cleaner.
- Veröffentlicht
- 2026-07-19 16:17:42
- Betroffene Versionen
- unknown
- Typ
- Betriebssystem
- Zuletzt geändert
- 2026-07-30 14:59:47
- Vektor
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H