Description
In the Linux kernel, the following vulnerability has been resolved: ping: Fix potentail NULL deref for /proc/net/icmp. After commit dbca1596bbb0 ("ping: convert to RCU lookups, get rid of rwlock"), we use RCU for ping sockets, but we should use spinlock for /proc/net/icmp to avoid a potential NULL deref mentioned in the previous patch. Let's go back to using spinlock there. Note we can convert ping sockets to use hlist instead of hlist_nulls because we do not use SLAB_TYPESAFE_BY_RCU for ping sockets.
Product status
dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 (git) before 5a08a32e624908890aa0a2eb442bb6a7669891a8
dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 (git) before 176cbb6da28f36506cc60a4bec4ab8df0c16713a
dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 (git) before ab5fb73ffa01072b4d8031cc05801fa1cb653bee
de3d723a3985f282a8c9e468d1e198616eb291c8 (git)
6.0
Any version before 6.0
6.1.24 (semver)
6.2.11 (semver)
6.3 (original_commit_for_fix)
References
git.kernel.org/...c/5a08a32e624908890aa0a2eb442bb6a7669891a8
git.kernel.org/...c/176cbb6da28f36506cc60a4bec4ab8df0c16713a
git.kernel.org/...c/ab5fb73ffa01072b4d8031cc05801fa1cb653bee
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.