]> git.baikalelectronics.ru Git - kernel.git/commit
xen-netfront: restore __skb_queue_tail() positioning in xennet_get_responses()
authorJan Beulich <jbeulich@suse.com>
Fri, 1 Jul 2022 06:56:52 +0000 (08:56 +0200)
committerJuergen Gross <jgross@suse.com>
Fri, 1 Jul 2022 08:01:23 +0000 (10:01 +0200)
commit940f162d7facf05b183d6550db0b77f10b37a11d
tree6d196d3a64dfc32078d8676363b64568cfdbbbd8
parent7c46115253152a7b7c7bedf2d61896959de1f824
xen-netfront: restore __skb_queue_tail() positioning in xennet_get_responses()

The commit referenced below moved the invocation past the "next" label,
without any explanation. In fact this allows misbehaving backends undue
control over the domain the frontend runs in, as earlier detected errors
require the skb to not be freed (it may be retained for later processing
via xennet_move_rx_slot(), or it may simply be unsafe to have it freed).

This is CVE-2022-33743 / XSA-405.

Fixes: 9bf1756dc970 ("xen networking: add basic XDP support for xen-netfront")
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
drivers/net/xen-netfront.c