CVE-2022-48721 Information
Description
In the Linux kernel the following vulnerability has been resolved:
net/smc: Forward wakeup to smc socket waitqueue after fallback
When we replace TCP with SMC and a fallback occurs there may be some socket waitqueue entries remaining in smc socket->wq such as eppoll_entries inserted by userspace applications.
After the fallback data flows over TCP/IP and only clcsocket->wq will be woken up. Applications can’t be notified by the entries which were inserted in smc socket->wq before fallback. So we need a mechanism to wake up smc socket->wq at the same time if some entries remaining in it.
The current workaround is to transfer the entries from smc socket->wq to clcsock->wq during the fallback. But this may cause a crash like this:
general protection fault probably for non-canonical address 0xdead000000000100: 0000 [1] PREEMPT SMP PTI
CPU: 3 PID: 0 Comm: swapper/3 Kdump: loaded Tainted: G E 5.16.0+ 107
RIP: 0010:__wake_up_common+0x65/0x170
Call Trace:
The crash is caused by privately transferring waitqueue entries from smc socket->wq to clcsock->wq. The owners of these entries such as epoll have no idea that the entries have been transferred to a different socket wait queue and still use original waitqueue spinlock (smc socket->wq.wait.lock) to make the entries operation exclusive but it doesn’t work. The operations to the entries such as removing from the waitqueue (now is clcsock->wq after fallback) may cause a crash when clcsock waitqueue is being iterated over at the moment.
This patch tries to fix this by no longer transferring wait queue entries privately but introducing own implementations of clcsock’s callback functions in fallback situation. The callback functions will forward the wakeup to smc socket->wq if clcsock->wq is actually woken up and smc socket->wq has remaining entries.
Reference
https://git.kernel.org/stable/c/0ef6049f664941bc0f75828b3a61877635048b27 https://git.kernel.org/stable/c/504078fbe9dd570d685361b57784a6050bc40aaa https://git.kernel.org/stable/c/341adeec9adad0874f29a0a1af35638207352a39
Share on: