Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work can be queued in bpf_ringbuf_commit() but the ring buffer is freed before the work executes. In the syzbot reproducer, a BPF program attached to sched_switch triggers bpf_ringbuf_commit(), queuing an irq_work. If the ring buffer is freed before this work executes, the irq_work thread may accesses freed memory. Calling `irq_work_sync(&rb->work)` ensures that all pending irq_work complete before freeing the buffer.
Product status
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before 47626748a2a00068dbbd5836d19076637b4e235b
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before de2ce6b14bc3e565708a39bdba3ef9162aeffc72
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before e1828c7a8d8135e21ff6adaaa9458c32aae13b11
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before 6451141103547f4efd774e912418a3b4318046c6
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before 10ca3b2eec384628bc9f5d8190aed9427ad2dde6
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before 430e15544f11f8de26b2b5109c7152f71b78295e
457f44363a8894135c85b7a9afd2bd8196db24ab (git) before 4e9077638301816a7d73fa1e1b4c1db4a7e3b59c
5.8
Any version before 5.8
5.10.247 (semver)
5.15.197 (semver)
6.1.159 (semver)
6.6.117 (semver)
6.12.58 (semver)
6.17.8 (semver)
6.18 (original_commit_for_fix)
References
git.kernel.org/...c/47626748a2a00068dbbd5836d19076637b4e235b
git.kernel.org/...c/de2ce6b14bc3e565708a39bdba3ef9162aeffc72
git.kernel.org/...c/e1828c7a8d8135e21ff6adaaa9458c32aae13b11
git.kernel.org/...c/6451141103547f4efd774e912418a3b4318046c6
git.kernel.org/...c/10ca3b2eec384628bc9f5d8190aed9427ad2dde6
git.kernel.org/...c/430e15544f11f8de26b2b5109c7152f71b78295e
git.kernel.org/...c/4e9077638301816a7d73fa1e1b4c1db4a7e3b59c