In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix crash passing ERRPTR to kthreadstop()
In testringbuffer()'s outfree cleanup loop, the check
!rb_threads[cpu] only catches NULL entries and misses entries that
hold an ERR_PTR.
rbthreads[] is static, so unassigned slots are NULL. But when
kthreadrunoncpu() fails for a cpu, it stores ERRPTR(-ENOMEM) (or
-EINTR) in rbthreads[cpu] before the creation loop jumps to outfree.
That entry is non-NULL, so the old !ptr check does not break, and the
cleanup proceeds to call kthreadstop() on the ERRPTR. kthreadstop()
then dereferences the bogus pointer, crashing the kernel during the
late_initcall self-test.
crash logs: BUG: kernel NULL pointer dereference, address: 000000000000001c Oops: 0002 [#1] SMP NOPTI CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy) RIP: 0010:kthreadstop+0x2e/0x220 RBX: fffffffffffffff4 CR2: 000000000000001c Call Trace: <TASK> testringbuffer+0x1ec/0x650 dooneinitcall+0x6c/0x2c0 kernelinitfreeable+0x21d/0x420 kernelinit+0x15/0x1c0 retfrom_fork+0x21b/0x320 </TASK> Kernel panic - not syncing: Fatal exception