CVE-2023-52516

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/03/2024
Last modified:
11/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> dma-debug: don&amp;#39;t call __dma_entry_alloc_check_leak() under free_entries_lock<br /> <br /> __dma_entry_alloc_check_leak() calls into printk -&gt; serial console<br /> output (qcom geni) and grabs port-&gt;lock under free_entries_lock<br /> spin lock, which is a reverse locking dependency chain as qcom_geni<br /> IRQ handler can call into dma-debug code and grab free_entries_lock<br /> under port-&gt;lock.<br /> <br /> Move __dma_entry_alloc_check_leak() call out of free_entries_lock<br /> scope so that we don&amp;#39;t acquire serial console&amp;#39;s port-&gt;lock under it.<br /> <br /> Trimmed-down lockdep splat:<br /> <br /> The existing dependency chain (in reverse order) is:<br /> <br /> -&gt; #2 (free_entries_lock){-.-.}-{2:2}:<br /> _raw_spin_lock_irqsave+0x60/0x80<br /> dma_entry_alloc+0x38/0x110<br /> debug_dma_map_page+0x60/0xf8<br /> dma_map_page_attrs+0x1e0/0x230<br /> dma_map_single_attrs.constprop.0+0x6c/0xc8<br /> geni_se_rx_dma_prep+0x40/0xcc<br /> qcom_geni_serial_isr+0x310/0x510<br /> __handle_irq_event_percpu+0x110/0x244<br /> handle_irq_event_percpu+0x20/0x54<br /> handle_irq_event+0x50/0x88<br /> handle_fasteoi_irq+0xa4/0xcc<br /> handle_irq_desc+0x28/0x40<br /> generic_handle_domain_irq+0x24/0x30<br /> gic_handle_irq+0xc4/0x148<br /> do_interrupt_handler+0xa4/0xb0<br /> el1_interrupt+0x34/0x64<br /> el1h_64_irq_handler+0x18/0x24<br /> el1h_64_irq+0x64/0x68<br /> arch_local_irq_enable+0x4/0x8<br /> ____do_softirq+0x18/0x24<br /> ...<br /> <br /> -&gt; #1 (&amp;port_lock_key){-.-.}-{2:2}:<br /> _raw_spin_lock_irqsave+0x60/0x80<br /> qcom_geni_serial_console_write+0x184/0x1dc<br /> console_flush_all+0x344/0x454<br /> console_unlock+0x94/0xf0<br /> vprintk_emit+0x238/0x24c<br /> vprintk_default+0x3c/0x48<br /> vprintk+0xb4/0xbc<br /> _printk+0x68/0x90<br /> register_console+0x230/0x38c<br /> uart_add_one_port+0x338/0x494<br /> qcom_geni_serial_probe+0x390/0x424<br /> platform_probe+0x70/0xc0<br /> really_probe+0x148/0x280<br /> __driver_probe_device+0xfc/0x114<br /> driver_probe_device+0x44/0x100<br /> __device_attach_driver+0x64/0xdc<br /> bus_for_each_drv+0xb0/0xd8<br /> __device_attach+0xe4/0x140<br /> device_initial_probe+0x1c/0x28<br /> bus_probe_device+0x44/0xb0<br /> device_add+0x538/0x668<br /> of_device_add+0x44/0x50<br /> of_platform_device_create_pdata+0x94/0xc8<br /> of_platform_bus_create+0x270/0x304<br /> of_platform_populate+0xac/0xc4<br /> devm_of_platform_populate+0x60/0xac<br /> geni_se_probe+0x154/0x160<br /> platform_probe+0x70/0xc0<br /> ...<br /> <br /> -&gt; #0 (console_owner){-...}-{0:0}:<br /> __lock_acquire+0xdf8/0x109c<br /> lock_acquire+0x234/0x284<br /> console_flush_all+0x330/0x454<br /> console_unlock+0x94/0xf0<br /> vprintk_emit+0x238/0x24c<br /> vprintk_default+0x3c/0x48<br /> vprintk+0xb4/0xbc<br /> _printk+0x68/0x90<br /> dma_entry_alloc+0xb4/0x110<br /> debug_dma_map_sg+0xdc/0x2f8<br /> __dma_map_sg_attrs+0xac/0xe4<br /> dma_map_sgtable+0x30/0x4c<br /> get_pages+0x1d4/0x1e4 [msm]<br /> msm_gem_pin_pages_locked+0x38/0xac [msm]<br /> msm_gem_pin_vma_locked+0x58/0x88 [msm]<br /> msm_ioctl_gem_submit+0xde4/0x13ac [msm]<br /> drm_ioctl_kernel+0xe0/0x15c<br /> drm_ioctl+0x2e8/0x3f4<br /> vfs_ioctl+0x30/0x50<br /> ...<br /> <br /> Chain exists of:<br /> console_owner --&gt; &amp;port_lock_key --&gt; free_entries_lock<br /> <br /> Possible unsafe locking scenario:<br /> <br /> CPU0 CPU1<br /> ---- ----<br /> lock(free_entries_lock);<br /> lock(&amp;port_lock_key);<br /> lock(free_entries_lock);<br /> lock(console_owner);<br /> <br /> *** DEADLOCK ***<br /> <br /> Call trace:<br /> dump_backtrace+0xb4/0xf0<br /> show_stack+0x20/0x30<br /> dump_stack_lvl+0x60/0x84<br /> dump_stack+0x18/0x24<br /> print_circular_bug+0x1cc/0x234<br /> check_noncircular+0x78/0xac<br /> __lock_acquire+0xdf8/0x109c<br /> lock_acquire+0x234/0x284<br /> console_flush_all+0x330/0x454<br /> consol<br /> ---truncated---

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.198 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.134 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.56 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.5.6 (excluding)