CVE-2024-53215 Information
Description
In the Linux kernel the following vulnerability has been resolved:
svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()
There’s issue as follows:
RPC: Registered rdma transport module.
RPC: Registered rdma backchannel transport module.
RPC: Unregistered rdma transport module.
RPC: Unregistered rdma backchannel transport module.
BUG: unable to handle page fault for address: fffffbfff80c609a
PGD 123fee067 P4D 123fee067 PUD 123fea067 PMD 10c624067 PTE 0
Oops: Oops: 0000 [1] PREEMPT SMP KASAN NOPTI
RIP: 0010:percpu_counter_destroy_many+0xf7/0x2a0
Call Trace:
If register_sysctl() return NULL then svc_rdma_proc_cleanup() will not destroy the percpu counters which init in svc_rdma_proc_init(). If CONFIG_HOTPLUG_CPU is enabled residual nodes may be in the ‘percpu_counters’ list. The above issue may occur once the module is removed. If the CONFIG_HOTPLUG_CPU configuration is not enabled memory leakage occurs. To solve above issue just destroy all percpu counters when register_sysctl() return NULL.
Reference
https://git.kernel.org/stable/c/1c9a99c89e45b22eb556fd2f3f729f2683f247d5 https://git.kernel.org/stable/c/20322edcbad82a60321a8615a99ca73a9611115f https://git.kernel.org/stable/c/94d2d6d398706ab7218a26d61e12919c4b498e09 https://git.kernel.org/stable/c/a12c897adf40b6e2b4a56e6912380c31bd7b2479 https://git.kernel.org/stable/c/ce89e742a4c12b20f09a43fec1b21db33f2166cd https://git.kernel.org/stable/c/ebf47215d46992caea660ec01cd618005d9e687a
Share on: