Description
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning as follows: drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn: '&entry->list' not removed from list In tsi148_dma_list_add(), the error path "goto err_dma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF. Fix by removeing it from list->entries before free().
Product status
b2383c90a9d691201b9aee557776694cde86a935 (git) before 5cc4eea715a3fcf4e516662f736dfee63979465f
b2383c90a9d691201b9aee557776694cde86a935 (git) before 51c0ad3b7c5b01f9314758335a13f157b05fa56d
b2383c90a9d691201b9aee557776694cde86a935 (git) before e6b0adff99edf246ba1f8d464530a0438cb1cbda
b2383c90a9d691201b9aee557776694cde86a935 (git) before a45ba33d398a821147d7e5f16ead7eb125e331e2
b2383c90a9d691201b9aee557776694cde86a935 (git) before 5d2b286eb034af114f67d9967fc3fbc1829bb712
b2383c90a9d691201b9aee557776694cde86a935 (git) before 1f5661388f43df3ac106ce93e67d8d22b16a78ff
b2383c90a9d691201b9aee557776694cde86a935 (git) before cf138759a7e92c75cfc1b7ba705e4108fe330edf
b2383c90a9d691201b9aee557776694cde86a935 (git) before 85db68fc901da52314ded80aace99f8b684c7815
b2383c90a9d691201b9aee557776694cde86a935 (git) before 357057ee55d3c99a5de5abe8150f7bca04f8e53b
4.2
Any version before 4.2
4.9.337 (semver)
4.14.303 (semver)
4.19.270 (semver)
5.4.229 (semver)
5.10.163 (semver)
5.15.86 (semver)
6.0.16 (semver)
6.1.2 (semver)
6.2 (original_commit_for_fix)
References
git.kernel.org/...c/5cc4eea715a3fcf4e516662f736dfee63979465f
git.kernel.org/...c/51c0ad3b7c5b01f9314758335a13f157b05fa56d
git.kernel.org/...c/e6b0adff99edf246ba1f8d464530a0438cb1cbda
git.kernel.org/...c/a45ba33d398a821147d7e5f16ead7eb125e331e2
git.kernel.org/...c/5d2b286eb034af114f67d9967fc3fbc1829bb712
git.kernel.org/...c/1f5661388f43df3ac106ce93e67d8d22b16a78ff
git.kernel.org/...c/cf138759a7e92c75cfc1b7ba705e4108fe330edf
git.kernel.org/...c/85db68fc901da52314ded80aace99f8b684c7815
git.kernel.org/...c/357057ee55d3c99a5de5abe8150f7bca04f8e53b