In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix mr leak in RESPSTERRRNR
rxerecheckmr() will increase mr's refcnt, so we should call rxeput(mr) to drop mr's refcnt in RESPSTERR_RNR to avoid below warning:
WARNING: CPU: 0 PID: 4156 at drivers/infiniband/sw/rxe/rxepool.c:259 _rxecleanup+0x1df/0x240 [rdmarxe] ... Call Trace: rxederegmr+0x4c/0x60 [rdmarxe] ibderegmruser+0xa8/0x200 [ibcore] ibmrpooldestroy+0x77/0xb0 [ibcore] nvmerdmadestroyqueueib+0x89/0x240 [nvmerdma] nvmerdmafreequeue+0x40/0x50 [nvmerdma] nvmerdmateardownioqueues.part.0+0xc3/0x120 [nvmerdma] nvmerdmaerrorrecoverywork+0x4d/0xf0 [nvmerdma] processonework+0x582/0xa40 ? pwqdecnrinflight+0x100/0x100 ? rwlockbug.part.0+0x60/0x60 workerthread+0x2a9/0x700 ? processonework+0xa40/0xa40 kthread+0x168/0x1a0 ? kthreadcompleteandexit+0x20/0x20 retfrom_fork+0x22/0x30
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50b35ad2864a9d66f802f9ce193d99bbef64e219",
"target": {
"file": "drivers/infiniband/sw/rxe/rxe_resp.c"
},
"deprecated": false,
"id": "CVE-2022-49929-013b0669",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"56205096794023712728988697188473887487",
"24215790160211230188223709083881219686",
"279396475854756330532631480180652548962",
"286243915192067763893496054118354361531",
"122611546984313973945783513093076871633"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b5f9a01fae42684648c2ee3cd9985f80c67ab9f7",
"target": {
"function": "read_reply",
"file": "drivers/infiniband/sw/rxe/rxe_resp.c"
},
"deprecated": false,
"id": "CVE-2022-49929-06c7e1a1",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1815.0,
"function_hash": "17812368680604885937119028523227249123"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50b35ad2864a9d66f802f9ce193d99bbef64e219",
"target": {
"function": "read_reply",
"file": "drivers/infiniband/sw/rxe/rxe_resp.c"
},
"deprecated": false,
"id": "CVE-2022-49929-38f2cee6",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1815.0,
"function_hash": "17812368680604885937119028523227249123"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b5f9a01fae42684648c2ee3cd9985f80c67ab9f7",
"target": {
"file": "drivers/infiniband/sw/rxe/rxe_resp.c"
},
"deprecated": false,
"id": "CVE-2022-49929-a8720544",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"56205096794023712728988697188473887487",
"24215790160211230188223709083881219686",
"279396475854756330532631480180652548962",
"286243915192067763893496054118354361531",
"122611546984313973945783513093076871633"
]
}
}
]