net: batman-adv: fix error handling
Published May 22, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.74%
Description
Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init().
Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case of any batadv_*_init() calls failure. This approach may work well, when there is some kind of indicator, which can tell which parts of batadv are initialized; but there isn't any.
All written above lead to cleaning up uninitialized fields. Even if we hide ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]
To fix these bugs we can unwind batadv_*_init() calls one by one. It is good approach for 2 reasons: 1) It fixes bugs on error handling path 2) It improves the performance, since we won't call unneeded batadv_*_free() functions.
So, this patch makes all batadv_*_init() clean up all allocated memory before returning with an error to no call correspoing batadv_*_free() and open-codes batadv_mesh_free() with proper order to avoid touching uninitialized fields.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.38StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.38
- Version 4.14.254StatusunaffectedConstraints<=4.14.*
- Version 4.19.215StatusunaffectedConstraints<=4.19.*
- Version 4.4.293StatusunaffectedConstraints<=4.4.*
- Version 4.9.289StatusunaffectedConstraints<=4.9.*
- Version 5.10.77StatusunaffectedConstraints<=5.10.*
- Version 5.14.16StatusunaffectedConstraints<=5.14.*
- Version 5.15StatusunaffectedConstraints<=*
- Version 5.4.157StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.38 · < 4.4.293
- ≥ 4.5 · < 4.9.289
- ≥ 4.10 · < 4.14.254
- ≥ 4.15 · < 4.19.215
- ≥ 4.20 · < 5.4.157
- ≥ 5.5 · < 5.10.77
- ≥ 5.11 · < 5.14.16
- 5.15
- 5.15
- 5.15
- 5.15
- 5.15
- 5.15
- 5.15
-
- Version c6c8fea29769StatusaffectedConstraints<6f68cd634856
- Version
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2021-47482 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282941 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34487 Advisory
- https://git.kernel.org/stable/c/07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20 Patch
- https://git.kernel.org/stable/c/0c6b199f09be489c48622537a550787fc80aea73 Patch
- https://git.kernel.org/stable/c/6422e8471890273994fe8cc6d452b0dcd2c9483e Patch
- https://git.kernel.org/stable/c/6f68cd634856f8ca93bafd623ba5357e0f648c68 Patch
- https://git.kernel.org/stable/c/a8f7359259dd5923adc6129284fdad12fc5db347 Patch
- https://git.kernel.org/stable/c/b0a2cd38553c77928ef1646ed1518486b1e70ae8 Patch
- https://git.kernel.org/stable/c/e50f957652190b5a88a8ebce7e5ab14ebd0d3f00 Patch
- https://git.kernel.org/stable/c/fbf150b16a3635634b7dfb7f229d8fcd643c6c51 Patch
- https://lore.kernel.org/linux-cve-announce/2024052238-CVE-2021-47482-5612@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2021-47482
- https://www.cve.org/CVERecord?id=CVE-2021-47482
Change history (0)
No recorded changes yet.