Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix double free in rxe_srq_from_init
In rxe_srq_from_init(), the queue pointer ‘q’ is assigned to ‘srq->rq.queue’ before copying the SRQ number to user space. If copy_to_user() fails, the function calls rxe_queue_cleanup() to free the queue, but leaves the now-invalid pointer in ‘srq->rq.queue’.
The caller of rxe_srq_from_init() (rxe_create_srq) eventually calls rxe_srq_cleanup() upon receiving the error, which triggers a second rxe_queue_cleanup() on the same memory, leading to a double free.
The call trace looks like this: kmem_cache_free+0x…/0x… rxe_queue_cleanup+0x1a/0x30 [rdma_rxe] rxe_srq_cleanup+0x42/0x60 [rdma_rxe] rxe_elem_release+0x31/0x70 [rdma_rxe] rxe_create_srq+0x12b/0x1a0 [rdma_rxe] ib_create_srq_user+0x9a/0x150 [ib_core]
Fix this by moving ‘srq->rq.queue = q’ after copy_to_user.
Details
- Affected product:
- AlmaLinux 9.2 ESU , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , TuxCare 9.6 ESU , Ubuntu 20.04 ELS
- Affected packages:
- kernel @ 5.14.0 (+7 more)
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 8 | Released |
107 kernels
|
| AlmaLinux 9 | Released |
109 kernels
|
| CentOS 8 | Released |
21 kernels
|
| CloudLinux OS 7h | Released |
103 kernels
|
| CloudLinux OS 8 | Released |
100 kernels
|
| Debian 11 | Will Not Fix |
37 kernels
|
| Debian 11 cloud | Will Not Fix |
17 kernels
|
| Debian 13 | Planned | — |
| Oracle Linux 8 | Released |
116 kernels
|
| Oracle Linux 9 | Released |
109 kernels
|
| RHEL 7 | In Progress | — |
| RHEL 8 | Released |
111 kernels
|
| RHEL 9 | Released |
107 kernels
|
| Rocky Linux 8 | Released |
89 kernels
|
| Rocky Linux 9 | Released |
87 kernels
|
| Ubuntu 22.04 | Planned | — |
| Ubuntu 24.04 | Planned | — |
| Ubuntu 24.04 AWS | Planned | — |