| From bippy-1.2.0 Mon Sep 17 00:00:00 2001 |
| From: Greg Kroah-Hartman <gregkh@kernel.org> |
| To: <linux-cve-announce@vger.kernel.org> |
| Reply-to: <cve@kernel.org>, <linux-kernel@vger.kernel.org> |
| Subject: CVE-2023-52899: Add exception protection processing for vd in axi_chan_handle_err function |
| |
| Description |
| =========== |
| |
| In the Linux kernel, the following vulnerability has been resolved: |
| |
| Add exception protection processing for vd in axi_chan_handle_err function |
| |
| Since there is no protection for vd, a kernel panic will be |
| triggered here in exceptional cases. |
| |
| You can refer to the processing of axi_chan_block_xfer_complete function |
| |
| The triggered kernel panic is as follows: |
| |
| [ 67.848444] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000060 |
| [ 67.848447] Mem abort info: |
| [ 67.848449] ESR = 0x96000004 |
| [ 67.848451] EC = 0x25: DABT (current EL), IL = 32 bits |
| [ 67.848454] SET = 0, FnV = 0 |
| [ 67.848456] EA = 0, S1PTW = 0 |
| [ 67.848458] Data abort info: |
| [ 67.848460] ISV = 0, ISS = 0x00000004 |
| [ 67.848462] CM = 0, WnR = 0 |
| [ 67.848465] user pgtable: 4k pages, 48-bit VAs, pgdp=00000800c4c0b000 |
| [ 67.848468] [0000000000000060] pgd=0000000000000000, p4d=0000000000000000 |
| [ 67.848472] Internal error: Oops: 96000004 [#1] SMP |
| [ 67.848475] Modules linked in: dmatest |
| [ 67.848479] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.100-emu_x2rc+ #11 |
| [ 67.848483] pstate: 62000085 (nZCv daIf -PAN -UAO +TCO BTYPE=--) |
| [ 67.848487] pc : axi_chan_handle_err+0xc4/0x230 |
| [ 67.848491] lr : axi_chan_handle_err+0x30/0x230 |
| [ 67.848493] sp : ffff0803fe55ae50 |
| [ 67.848495] x29: ffff0803fe55ae50 x28: ffff800011212200 |
| [ 67.848500] x27: ffff0800c42c0080 x26: ffff0800c097c080 |
| [ 67.848504] x25: ffff800010d33880 x24: ffff80001139d850 |
| [ 67.848508] x23: ffff0800c097c168 x22: 0000000000000000 |
| [ 67.848512] x21: 0000000000000080 x20: 0000000000002000 |
| [ 67.848517] x19: ffff0800c097c080 x18: 0000000000000000 |
| [ 67.848521] x17: 0000000000000000 x16: 0000000000000000 |
| [ 67.848525] x15: 0000000000000000 x14: 0000000000000000 |
| [ 67.848529] x13: 0000000000000000 x12: 0000000000000040 |
| [ 67.848533] x11: ffff0800c0400248 x10: ffff0800c040024a |
| [ 67.848538] x9 : ffff800010576cd4 x8 : ffff0800c0400270 |
| [ 67.848542] x7 : 0000000000000000 x6 : ffff0800c04003e0 |
| [ 67.848546] x5 : ffff0800c0400248 x4 : ffff0800c4294480 |
| [ 67.848550] x3 : dead000000000100 x2 : dead000000000122 |
| [ 67.848555] x1 : 0000000000000100 x0 : ffff0800c097c168 |
| [ 67.848559] Call trace: |
| [ 67.848562] axi_chan_handle_err+0xc4/0x230 |
| [ 67.848566] dw_axi_dma_interrupt+0xf4/0x590 |
| [ 67.848569] __handle_irq_event_percpu+0x60/0x220 |
| [ 67.848573] handle_irq_event+0x64/0x120 |
| [ 67.848576] handle_fasteoi_irq+0xc4/0x220 |
| [ 67.848580] __handle_domain_irq+0x80/0xe0 |
| [ 67.848583] gic_handle_irq+0xc0/0x138 |
| [ 67.848585] el1_irq+0xc8/0x180 |
| [ 67.848588] arch_cpu_idle+0x14/0x2c |
| [ 67.848591] default_idle_call+0x40/0x16c |
| [ 67.848594] do_idle+0x1f0/0x250 |
| [ 67.848597] cpu_startup_entry+0x2c/0x60 |
| [ 67.848600] rest_init+0xc0/0xcc |
| [ 67.848603] arch_call_rest_init+0x14/0x1c |
| [ 67.848606] start_kernel+0x4cc/0x500 |
| [ 67.848610] Code: eb0002ff 9a9f12d6 f2fbd5a2 f2fbd5a3 (a94602c1) |
| [ 67.848613] ---[ end trace 585a97036f88203a ]--- |
| |
| The Linux kernel CVE team has assigned CVE-2023-52899 to this issue. |
| |
| |
| Affected and fixed versions |
| =========================== |
| |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 4.19.271 with commit f534dc438828cc3f1f8c6895b8bdfbef079521fb |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 5.4.230 with commit 53dd833fd0a2d8f0118d01ea063a70652689d31e |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 5.10.165 with commit 20d0a6d17e85a8a816a64fa7d7cae616f1617833 |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 5.15.90 with commit 5054d001ffaf76155637c5e5b922c11016cd6a5d |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 6.1.8 with commit 51a7ad5b60efac65691729d10745c28fa1016b96 |
| Issue introduced in 4.17 with commit 1fe20f1b84548bbcf48b6659ea171cd46618ea3a and fixed in 6.2 with commit 57054fe516d59d03a7bcf1888e82479ccc244f87 |
| |
| Please see https://www.kernel.org for a full list of currently supported |
| kernel versions by the kernel community. |
| |
| Unaffected versions might change over time as fixes are backported to |
| older supported kernel versions. The official CVE entry at |
| https://cve.org/CVERecord/?id=CVE-2023-52899 |
| will be updated if fixes are backported, please check that for the most |
| up to date information about this issue. |
| |
| |
| Affected files |
| ============== |
| |
| The file(s) affected by this issue are: |
| drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c |
| |
| |
| Mitigation |
| ========== |
| |
| The Linux kernel CVE team recommends that you update to the latest |
| stable kernel version for this, and many other bugfixes. Individual |
| changes are never tested alone, but rather are part of a larger kernel |
| release. Cherry-picking individual commits is not recommended or |
| supported by the Linux kernel community at all. If however, updating to |
| the latest release is impossible, the individual changes to resolve this |
| issue can be found at these commits: |
| https://git.kernel.org/stable/c/f534dc438828cc3f1f8c6895b8bdfbef079521fb |
| https://git.kernel.org/stable/c/53dd833fd0a2d8f0118d01ea063a70652689d31e |
| https://git.kernel.org/stable/c/20d0a6d17e85a8a816a64fa7d7cae616f1617833 |
| https://git.kernel.org/stable/c/5054d001ffaf76155637c5e5b922c11016cd6a5d |
| https://git.kernel.org/stable/c/51a7ad5b60efac65691729d10745c28fa1016b96 |
| https://git.kernel.org/stable/c/57054fe516d59d03a7bcf1888e82479ccc244f87 |