In the Linux kernel, the following vulnerability has been resolved:mac802154: check local interfaces before deleting sdata listsyzkaller reported a corrupted list in ieee802154_if_remove. [1]Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4hardware device from the system.CPU0 CPU1==== ====genl_family_rcv_msg_doit ieee802154_unregister_hwieee802154_del_iface ieee802154_remove_interfacesrdev_del_virtual_intf_deprecated list_del(&sdata->list)ieee802154_if_removelist_del_rcuThe net device has been unregistered, since the rcu grace period,unregistration must be run before ieee802154_if_remove.To avoid this issue, add a check for local->interfaces before deletingsdata list.[1]kernel BUG at lib/list_debug.c:58!Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTICPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 <0f> 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000RBP: ffff88805b278dd8 R08: ffffffff8174a12c R09: 1ffffffff2852f0dR10: dffffc0000000000 R11: fffffbfff2852f0e R12: dffffc0000000000R13: dffffc0000000000 R14: dead000000000100 R15: ffff88805b278cc0FS: 0000555572f94380(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 000056262e4a3000 CR3: 0000000078496000 CR4: 00000000003526f0DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400Call Trace:
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/w4zu/Debian_security