In the Linux kernel, the following vulnerability has been resolved:bpf: Fix deadlock between rcu_tasks_trace and event_mutex.Fix the following deadlock:CPU A_free_event() perf_kprobe_destroy() mutex_lock(&event_mutex) perf_trace_event_unreg() synchronize_rcu_tasks_trace()There are several paths where _free_event() grabs event_mutexand calls sync_rcu_tasks_trace. Above is one such case.CPU Bbpf_prog_test_run_syscall() rcu_read_lock_trace() bpf_prog_run_pin_on_cpu() bpf_prog_load() bpf_tracing_func_proto() trace_set_clr_event() mutex_lock(&event_mutex)Delegate trace_set_clr_event() to workqueue to avoidsuch lock dependency.
No PoCs from references.
- https://github.com/w4zu/Debian_security