io_uring/poll: don't reissue in case of poll race on multishot request
Published Aug 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
A previous commit fixed a poll race that can occur, but it's only applicable for multishot requests. For a multishot request, we can safely ignore a spurious wakeup, as we never leave the waitqueue to begin with.
A blunt reissue of a multishot armed request can cause us to leak a buffer, if they are ring provided. While this seems like a bug in itself, it's not really defined behavior to reissue a multishot request directly. It's less efficient to do so as well, and not required to rearm anything like it is for singleshot poll requests.
Affected products
-
- Version 6.1.7StatusaffectedConstraints<6.1.8
- Version
-
- Version 6e5aedb9324aStatusaffectedConstraints<8caa03f10bf9
- Version c06015ebc436StatusaffectedConstraints<36fc7317cdb1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- 6.1.7
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-52895 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2306423 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59606 Advisory
- https://git.kernel.org/stable/c/36fc7317cdb16cfeae0f879916995037bb615ac4 Patch
- https://git.kernel.org/stable/c/8caa03f10bf92cb8657408a6ece6a8a73f96ce13 Patch
- https://lore.kernel.org/linux-cve-announce/2024082111-CVE-2023-52895-5be2@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52895
- https://www.cve.org/CVERecord?id=CVE-2023-52895
Change history (0)
No recorded changes yet.