Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() struct irdma_create_ah_resp { // 8 bytes, no padding __u32 ah_id; // offset 0 - SET (uresp.ah_id = ah->sc_ah.ah_info.ah_idx) __u8 rsvd[4]; // offset 4 - NEVER SET <- LEAK }; rsvd[4]: 4 bytes of stack memory leaked unconditionally. Only ah_id is assigned before ib_respond_udata(). The reserved members of the structure were not zeroed.
Product status
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 1f70df004fdd944653013ccc2e1dfd472a693b46
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 14b47c07c69930254f549a17ee245c80a65b1609
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 2fd37450d271d74b3847baed284f9cfdf198c6f8
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before cfe962216c164fe2b1c1fb6ac925a7413f5abc84
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before c9bd0007c4bdb7806bbd323287e50f9cf467c51a
b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 74586c6da9ea222a61c98394f2fc0a604748438c
5.14
Any version before 5.14
5.15.203 (semver)
6.1.167 (semver)
6.6.130 (semver)
6.12.77 (semver)
6.18.17 (semver)
6.19.7 (semver)
7.0 (original_commit_for_fix)
References
git.kernel.org/...c/1f70df004fdd944653013ccc2e1dfd472a693b46
git.kernel.org/...c/14b47c07c69930254f549a17ee245c80a65b1609
git.kernel.org/...c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
git.kernel.org/...c/2fd37450d271d74b3847baed284f9cfdf198c6f8
git.kernel.org/...c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84
git.kernel.org/...c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a
git.kernel.org/...c/74586c6da9ea222a61c98394f2fc0a604748438c