In the Linux kernel, the following vulnerability has been resolved:
igb: revert rtnl_lock() that causes deadlock
The commit 6faee3d4ee8b ("igb: Add lock to avoid data race") adds rtnl_lock to eliminate a false data race shown below
(FREE from device detaching) | (USE from netdev core) igbremove | igbndogetvfconfig igbdisablesriov | vf >= adapter->vfsallocatedcount? kfree(adapter->vfdata) | adapter->vfsallocatedcount = 0 | | memcpy(... adapter->vf_data[vf]
The above race will never happen and the extra rtnl_lock causes deadlock below
[ 141.420169] <TASK> [ 141.420672] _schedule+0x2dd/0x840 [ 141.421427] schedule+0x50/0xc0 [ 141.422041] schedulepreemptdisabled+0x11/0x20 [ 141.422678] _mutexlock.isra.13+0x431/0x6b0 [ 141.423324] unregisternetdev+0xe/0x20 [ 141.423578] igbvfremove+0x45/0xe0 [igbvf] [ 141.423791] pcideviceremove+0x36/0xb0 [ 141.423990] devicereleasedriverinternal+0xc1/0x160 [ 141.424270] pcistopbusdevice+0x6d/0x90 [ 141.424507] pcistopandremovebusdevice+0xe/0x20 [ 141.424789] pciiovremovevirtfn+0xba/0x120 [ 141.425452] sriovdisable+0x2f/0xf0 [ 141.425679] igbdisablesriov+0x4e/0x100 [igb] [ 141.426353] igbremove+0xa0/0x130 [igb] [ 141.426599] pcideviceremove+0x36/0xb0 [ 141.426796] devicereleasedriverinternal+0xc1/0x160 [ 141.427060] driverdetach+0x44/0x90 [ 141.427253] busremovedriver+0x55/0xe0 [ 141.427477] pciunregisterdriver+0x2a/0xa0 [ 141.428296] _x64sysdeletemodule+0x141/0x2b0 [ 141.429126] ? mntputnoexpire+0x4a/0x240 [ 141.429363] ? syscalltraceenter.isra.19+0x126/0x1a0 [ 141.429653] dosyscall64+0x5b/0x80 [ 141.429847] ? exittousermodeprepare+0x14d/0x1c0 [ 141.430109] ? syscallexittousermode+0x12/0x30 [ 141.430849] ? dosyscall64+0x67/0x80 [ 141.431083] ? syscallexittousermodeprepare+0x183/0x1b0 [ 141.431770] ? syscallexittousermode+0x12/0x30 [ 141.432482] ? dosyscall64+0x67/0x80 [ 141.432714] ? excpagefault+0x64/0x140 [ 141.432911] entrySYSCALL64afterhwframe+0x72/0xdc
Since the igbdisablesriov() will call pcidisablesriov() before releasing any resources, the netdev core will synchronize the cleanup to avoid any races. This patch removes the useless rtnl_(un)lock to guarantee correctness.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7d845e9a485f287181ff81567c3900a8e7ad1e28",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-029121d2",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@65f69851e44d71248b952a687e44759a7abb5016",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-0f94ad43",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@62a64645749926f9d75af82a96440941f22b046f",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-15faa3af",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7d845e9a485f287181ff81567c3900a8e7ad1e28",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-4275fcb5",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@62a64645749926f9d75af82a96440941f22b046f",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-4e4ee076",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d2626e10709ff8474ffd1a9db3cf4647569e89c",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-5787ec96",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd1e320ac0958298c2774605ad050483f33a21f2",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-5ae3c6bf",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d2626e10709ff8474ffd1a9db3cf4647569e89c",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-5e158261",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66e5577cabc3d463eea540332727929d0ace41c6",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-61245b55",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0dabb72b923e17cb3b4ac99ea1adc9ef35116930",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-6f007bd5",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de91528d8ba274c614a2265077d695c61e31fd43",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-7153d303",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de91528d8ba274c614a2265077d695c61e31fd43",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-747202a2",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd1e320ac0958298c2774605ad050483f33a21f2",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-bce07eb2",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66e5577cabc3d463eea540332727929d0ace41c6",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-c2dd6ee0",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170837041362912932086428170765667118476",
"143832687818728091350818519913048453122",
"242269464472886349329787258635603998570",
"339454136312374945458796998997801341058",
"242173972726120265447042743484043926425",
"84041622039317715091831905609555291645"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@65f69851e44d71248b952a687e44759a7abb5016",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-d9cfec21",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1083.0,
"function_hash": "260239173225342358391549278397603242922"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0dabb72b923e17cb3b4ac99ea1adc9ef35116930",
"target": {
"function": "igb_remove",
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"id": "CVE-2023-53060-e5b94d77",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1104.0,
"function_hash": "281982648481706144811536412027550853567"
}
}
]