In the Linux kernel, the following vulnerability has been resolved:
io_uring: wait interruptibly for request completions on exit
WHen the ring exits, cleanup is done and the final cancelation and waiting on completions is done by ioringexitwork. That function is invoked by kworker, which doesn't take any signals. Because of that, it doesn't really matter if we wait for completions in TASKINTERRUPTIBLE or TASK_UNINTERRUPTIBLE state. However, it does matter to the hung task detection checker!
Normally we expect cancelations and completions to happen rather quickly. Some test cases, however, will exit the ring and park the owning task stopped (eg via SIGSTOP). If the owning task needs to run taskwork to complete requests, then ioringexitwork won't make any progress until the task is runnable again. Hence ioringexit_work can trigger the hung task detection, which is particularly problematic if panic-on-hung-task is enabled.
As the ring exit doesn't take signals to begin with, have it wait interruptibly rather than uninterruptibly. io_uring has a separate stuck-exit warning that triggers independently anyway, so we're not really missing anything by making this switch.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28e649dc9947e6525c95e32aa9a8e147925e3f56",
"target": {
"file": "io_uring/io_uring.c"
},
"id": "CVE-2023-53461-19d16026",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"331557267931582703024101887004048265186",
"334599777528642052373374518785902480169",
"149658250765016658510930602665619991678",
"109338042268382281056849672660934581373",
"35389267651510228773128774565150704023",
"231536729074632392066113092116325947529",
"11882210831876225069409426764861837380",
"142017501994705065575352219262948248020"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4826c59453b3b4677d6bf72814e7ababdea86949",
"target": {
"file": "io_uring/io_uring.c"
},
"id": "CVE-2023-53461-246b4517",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"331557267931582703024101887004048265186",
"334599777528642052373374518785902480169",
"149658250765016658510930602665619991678",
"109338042268382281056849672660934581373",
"5073778154318050824110460141117463297",
"160180130931138826183912993672371163359",
"11882210831876225069409426764861837380",
"142017501994705065575352219262948248020"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e29835366138389bfad3b31ea06960d0a77bf77",
"target": {
"file": "io_uring/io_uring.c"
},
"id": "CVE-2023-53461-27a6c341",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"331557267931582703024101887004048265186",
"334599777528642052373374518785902480169",
"149658250765016658510930602665619991678",
"109338042268382281056849672660934581373",
"35389267651510228773128774565150704023",
"231536729074632392066113092116325947529",
"11882210831876225069409426764861837380",
"142017501994705065575352219262948248020"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b50d6e06cca7b67a3d73ca660dda27662b76e6ea",
"target": {
"file": "io_uring/io_uring.c"
},
"id": "CVE-2023-53461-9d790983",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"331557267931582703024101887004048265186",
"334599777528642052373374518785902480169",
"149658250765016658510930602665619991678",
"109338042268382281056849672660934581373",
"5073778154318050824110460141117463297",
"160180130931138826183912993672371163359",
"11882210831876225069409426764861837380",
"142017501994705065575352219262948248020"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]