[lvc-project] [PATCH 0/2] can: j1939: avoid possible use-after-free when j1939_can_rx_register fails
Fedor Pchelkin
pchelkin at ispras.ru
Fri May 26 20:19:08 MSK 2023
The patch series fixes a possible racy use-after-free scenario described
in 2/2: if j1939_can_rx_register() fails then the concurrent thread may
have already read the invalid priv structure.
The 1/2 makes j1939_netdev_lock a mutex so that access to
j1939_can_rx_register() can be serialized without changing GFP_KERNEL to
GFP_ATOMIC inside can_rx_register(). This seems to be safe.
Note that the patch series has been tested only via Syzkaller and not with
a real device.
More information about the lvc-project
mailing list