mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: CVE-2022-49689: xen-blkfront: Handle NULL gendisk
       [not found] <2025022627-CVE-2022-49689-06fb@gregkh>
@ 2025-02-26  7:43 ` Juergen Gross
  0 siblings, 0 replies; only message in thread
From: Juergen Gross @ 2025-02-26  7:43 UTC (permalink / raw)
  To: cve, linux-kernel; +Cc: Greg Kroah-Hartman


[-- Attachment #1.1.1: Type: text/plain, Size: 1270 bytes --]

On 26.02.25 03:24, Greg Kroah-Hartman wrote:
> Description
> ===========
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> xen-blkfront: Handle NULL gendisk
> 
> When a VBD is not fully created and then closed, the kernel can have a
> NULL pointer dereference:
> 
> The reproducer is trivial:
> 
> [user@dom0 ~]$ sudo xl block-attach work backend=sys-usb vdev=xvdi target=/dev/sdz
> [user@dom0 ~]$ xl block-list work
> Vdev  BE  handle state evt-ch ring-ref BE-path
> 51712 0   241    4     -1     -1       /local/domain/0/backend/vbd/241/51712
> 51728 0   241    4     -1     -1       /local/domain/0/backend/vbd/241/51728
> 51744 0   241    4     -1     -1       /local/domain/0/backend/vbd/241/51744
> 51760 0   241    4     -1     -1       /local/domain/0/backend/vbd/241/51760
> 51840 3   241    3     -1     -1       /local/domain/3/backend/vbd/241/51840
>                   ^ note state, the /dev/sdz doesn't exist in the backend
> 
> [user@dom0 ~]$ sudo xl block-detach work xvdi

Please revoke this CVE. As the reproducer recipe is clearly showing, the
bug can be triggered by host admin actions only. There is no way an unprivileged
user on the host or in the guest could trigger the issue.


Juergen

[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]

[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2025-02-26  7:43 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <2025022627-CVE-2022-49689-06fb@gregkh>
2025-02-26  7:43 ` CVE-2022-49689: xen-blkfront: Handle NULL gendisk Juergen Gross

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®