** Description changed:
- TBD
+ [Impact]
+
+ If the socket buffer array of a tap queue is full, a received package
+ needs to be dropped. Currently, the check for the array being full is
+ performed lockless, which might lead to use-after-free errors if the
+ socket buffer array has been resized.
+
+ [Test Case]
+
+ TBD.
+
+ [Regression Potential]
+
+ The check for the array being full is simply dropped. In case the array
+ is full, subsequent frame handling will fail and the frame is eventually
+ dropped. A regression would manifest itself if the frame is not dropped
+ for whatever reason and inserted into the (ring) buffer, overwriting the
+ oldest frame in the buffer.
** Changed in: linux (Ubuntu)
Status: Incomplete => Invalid
** Changed in: linux (Ubuntu Bionic)
Status: Incomplete => Confirmed
--
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1889735
Title:
tap: use after free
Status in linux package in Ubuntu:
Invalid
Status in linux source package in Bionic:
Confirmed
Bug description:
[Impact]
If the socket buffer array of a tap queue is full, a received package
needs to be dropped. Currently, the check for the array being full is
performed lockless, which might lead to use-after-free errors if the
socket buffer array has been resized.
[Test Case]
TBD.
[Regression Potential]
The check for the array being full is simply dropped. In case the
array is full, subsequent frame handling will fail and the frame is
eventually dropped. A regression would manifest itself if the frame is
not dropped for whatever reason and inserted into the (ring) buffer,
overwriting the oldest frame in the buffer.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1889735/+subscriptions
--
Mailing list: https://launchpad.net/~kernel-packages
Post to : [email protected]
Unsubscribe : https://launchpad.net/~kernel-packages
More help : https://help.launchpad.net/ListHelp