net: dsa: improve shutdown sequence
In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sverdlin presents 2 problems during shutdown with the lan9303 driver. One is specific to lan9303 and the other just happens to reproduce there. The first problem is that lan9303 is unique among DSA drivers in that it calls dev_get_drvdata() at "arbitrary runtime" (not probe, not shutdown, not remove): phy_state_machine() -> ... -> dsa_user_phy_read() -> ds->ops->phy_read() -> lan9303_phy_read() -> chip->ops->phy_read() -> lan9303_mdio_phy_read() -> dev_get_drvdata() But we never stop the phy_state_machine(), so it may continue to run after dsa_switch_shutdown(). Our common pattern in all DSA drivers is to set drvdata to NULL to suppress the remove() method that may come afterwards. But in this case it will result in an NPD. The second problem is that the way in which we set dp->conduit->dsa_ptr = NULL; is concurrent with receive packet processing. dsa_switch_rcv() checks once whether dev->dsa_ptr is NULL, but afterwards, rather than continuing to use that non-NULL value, dev->dsa_ptr is dereferenced again and again without NULL checks: dsa_conduit_find_user() and many other places. In between dereferences, there is no locking to ensure that what was valid once continues to be valid. Both problems have the common aspect that closing the conduit interface solves them. In the first case, dev_close(conduit) triggers the NETDEV_GOING_DOWN event in dsa_user_netdevice_event() which closes user ports as well. dsa_port_disable_rt() calls phylink_stop(), which synchronously stops the phylink state machine, and ds->ops->phy_read() will thus no longer call into the driver after this point. In the second case, dev_close(conduit) should do this, as per Documentation/networking/driver.rst: | Quiescence | ---------- | | After the ndo_stop routine has been called, the hardware must | not receive or transmit any data. All in flight packets must | be aborted. If necessary, poll or wait for completion of | any reset commands. So it should be sufficient to ensure that later, when we zeroize conduit->dsa_ptr, there will be no concurrent dsa_switch_rcv() call on this conduit. The addition of the netif_device_detach() function is to ensure that ioctls, rtnetlinks and ethtool requests on the user ports no longer propagate down to the driver - we're no longer prepared to handle them. The race condition actually did not exist when commit 0650bf52b31f ("net: dsa: be compatible with masters which unregister on shutdown") first introduced dsa_switch_shutdown(). It was created later, when we stopped unregistering the user interfaces from a bad spot, and we just replaced that sequence with a racy zeroization of conduit->dsa_ptr (one which doesn't ensure that the interfaces aren't up).
- Yayın
- 21 Eki 2024
- Güncelleme
- 8 Eyl 2026
- EPSS
- %0,2 · 6. yüzdelik
- CWE
- CWE-367
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
18
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 18 / 40 · 4.7 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,2
CISA SSVC kararı
- Sömürü
- yok
- Otomatikleştirilebilir
- hayır
- Teknik etki
- kısmi
Vulnrichment: CISA'nın karar ağacı girdileri.
Etkilenen sistemler
| Üretici | Ürün | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Etkilenen sürümler
NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.
- linux linux kernel5.15.155 ve sonrası · 5.16 öncesi
- linux linux kernel5.16.10 ve sonrası · 5.17 öncesi
- linux linux kernel5.17 ve sonrası · 6.10.14 öncesi
- linux linux kernel6.11 ve sonrası · 6.11.3 öncesi
- linux linux kernel6.12
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 89b60402d43cdab4387dbbf24afebda5cf092ae7, 5.17etkilenir
- ff45899e732e57088985e3a497b1d9100571c0f5 ve sonrası · 87bd909a7014e32790e8c759d5b7694a95778ca5 öncesietkilenir · git
- ee534378f00561207656663d93907583958339ae ve sonrası · ab9e90619b6339becc5415647ae154a9a46a044d öncesietkilenir · git
- ee534378f00561207656663d93907583958339ae ve sonrası · 2e93bf719462ac6d23c881c8b93e5dc9bf5ab7f5 öncesietkilenir · git
- ee534378f00561207656663d93907583958339ae ve sonrası · ab5d3420a1120950703dbdc33698b28a6ebc3d23 öncesietkilenir · git
- ee534378f00561207656663d93907583958339ae ve sonrası · b4a65d479213fe84ecb14e328271251eebe69492 öncesietkilenir · git
- ee534378f00561207656663d93907583958339ae ve sonrası · 6c24a03a61a245fe34d47582898331fa034b6ccd öncesietkilenir · git
- 5.15.155 ve sonrası · 5.15.176 öncesietkilenir · semver
- 5.16.10 ve sonrası · 5.17 öncesietkilenir · semver
- 5.17 öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.170-1 öncesi | 6.1.170-1 |
| Debian:13 | linux | 6.11.4-1 öncesi | 6.11.4-1 |
| openSUSE:Leap 15.6 | dtb-aarch64 | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| openSUSE:Leap 15.6 | kernel-debug | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| openSUSE:Leap 15.6 | kernel-kvmsmall | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| openSUSE:Leap 15.6 | kernel-obs-qa | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6_Update_8 | 1-150600.13.3.2 öncesi | 1-150600.13.3.2 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6_Update_8 | 1-150600.13.3.2 öncesi | 1-150600.13.3.2 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6-RT_Update_8 | 1-150600.1.3.1 öncesi | 1-150600.1.3.1 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6-RT_Update_8 | 1-150600.1.3.1 öncesi | 1-150600.1.3.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-64kb | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-64kb | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default-base | 6.4.0-150600.23.38.1.150600.12.16.2 öncesi | 6.4.0-150600.23.38.1.150600.12.16.2 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default-base | 6.4.0-150600.23.38.1.150600.12.16.2 öncesi | 6.4.0-150600.23.38.1.150600.12.16.2 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-source | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-source | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-zfcpdump | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-zfcpdump | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-docs | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-docs | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-obs-build | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-obs-build | 6.4.0-150600.23.38.1 öncesi | 6.4.0-150600.23.38.1 |
+16
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Hemen
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Hemen
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Hemen
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77Bu hafta
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77Bu hafta
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77Bu hafta
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 2e93bf719462ac6d23c881c8b93e5dc9bf5ab7f5 | Üretici (CNA) |
| Linux Linux | 5.15.176 | Üretici (CNA) |
| Linux Linux | 5.17 | Üretici (CNA) |
| Linux Linux | 6c24a03a61a245fe34d47582898331fa034b6ccd | Üretici (CNA) |
| Linux Linux | 87bd909a7014e32790e8c759d5b7694a95778ca5 | Üretici (CNA) |
| Linux Linux | ab5d3420a1120950703dbdc33698b28a6ebc3d23 | Üretici (CNA) |
| Linux Linux | ab9e90619b6339becc5415647ae154a9a46a044d | Üretici (CNA) |
| Linux Linux | b4a65d479213fe84ecb14e328271251eebe69492 | Üretici (CNA) |
| debian:linux | 6.1.170-1 · Debian:12 | Paket deposu (OSV) |
| opensuse:kernel-azure | 6.4.0-150600.8.26.1 · openSUSE:Leap 15.6 | Paket deposu (OSV) |
| opensuse:kernel-source-azure | 6.4.0-150600.8.26.1 · openSUSE:Leap 15.6 | Paket deposu (OSV) |
| opensuse:kernel-syms-azure | 6.4.0-150600.8.26.1 · openSUSE:Leap 15.6 | Paket deposu (OSV) |
| suse:kernel-64kb | 6.4.0-150600.23.38.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP6 | Paket deposu (OSV) |
| suse:kernel-azure | 6.4.0-150600.8.26.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Paket deposu (OSV) |
| suse:kernel-default | 6.4.0-150600.23.38.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP6 | Paket deposu (OSV) |
| suse:kernel-default-base | 6.4.0-150600.23.38.1.150600.12.16.2 · SUSE:Linux Enterprise Module for Basesystem 15 SP6 | Paket deposu (OSV) |
| suse:kernel-docs | 6.4.0-150600.23.38.1 · SUSE:Linux Enterprise Module for Development Tools 15 SP6 | Paket deposu (OSV) |
| suse:kernel-source | 6.4.0-150600.23.38.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP6 | Paket deposu (OSV) |
| suse:kernel-source-azure | 6.4.0-150600.8.26.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Paket deposu (OSV) |
| suse:kernel-syms-azure | 6.4.0-150600.8.26.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Paket deposu (OSV) |
| suse:kernel-zfcpdump | 6.4.0-150600.23.38.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP6 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
- CVE-2025-38352274 gün araylaposix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()KEV61Bu hafta
- CVE-2024-5023419 gün araylawifi: iwlegacy: Clear stale interrupts before resuming device28İzleyin
- CVE-2024-4388262 gün araylaexec: Fix ToCToU between perm check and set-uid/gid usage28İzleyin
- CVE-2021-47280153 gün arayladrm: Fix use-after-free read in drm_getunique()28İzleyin
- CVE-2024-26974173 gün araylacrypto: qat - resolve race condition during AER recovery28İzleyin
- CVE-2023-1295481 gün araylaPrivilege escalation with IO_RING_OP_CLOSE in the Linux Kernel28İzleyin
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Saldırı koşulları
- Sisteme yerel erişimi olan biri tetikleyebilir.
- Düşük yetkili bir hesap yeterli.
- Kullanıcının bir şey yapması gerekmez.
- Zamanlama ya da yapılandırma gibi özel koşullar gerekir.
Başarılı olursa
- Gizlilik
- yok
- Bütünlük
- yok
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Yerel
- Karmaşıklık
- Yüksek
- Gereken yetki
- Düşük
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yok
- Bütünlük etkisi
- Yok
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
CWE-367 · Time-of-check Time-of-use (TOCTOU) Race ConditionCVSS vektörü
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd-primary
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Saldırı desenleri (CAPEC)
ATT&CK teknikleri
—
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/2e93bf719462ac6d23c881c8b93e5dc9bf5ab7f5
- git.kernel.org/stable/c/6c24a03a61a245fe34d47582898331fa034b6ccd
- git.kernel.org/stable/c/87bd909a7014e32790e8c759d5b7694a95778ca5
- git.kernel.org/stable/c/ab5d3420a1120950703dbdc33698b28a6ebc3d23
- git.kernel.org/stable/c/ab9e90619b6339becc5415647ae154a9a46a044d
- git.kernel.org/stable/c/b4a65d479213fe84ecb14e328271251eebe69492
- cert-portal.siemens.com/productcert/html/ssa-019113.html
- cert-portal.siemens.com/productcert/html/ssa-082556.html
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.