In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 Currently rsv_qp is freed before ib_unregister_device() is called on HIP08. During the time interval, users can still dereg MR and rsv_qp will be used in this process, leading to a UAF. Move the release of rsv_qp after calling ib_unregister_device() to fix it.
Product | Vendor | Version |
---|---|---|
Linux | Linux | < 5.2.20 |
Linux | Linux | < 175af15551ed5aa6af16ff97aff75cfffb42da21 |