Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 2 days, 5 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
gpio: shared: fix deadlock on shared proxy's parent removal

In the Linux kernel, the following vulnerability has been resolved: gpio: shared: fix deadlock on shared proxy's parent removal Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set") used the mutex embedded in struct gpio_shared_entry to protect the offset field which now can be modified after assignment. The critical section however is too wide and introduced a potential deadlock on the removal of the shared GPIO proxy's parent. Make the critical section shorter - only protect the offset when it's being read. While at it: mention the fact that the entry lock is now also used to protect against concurrent access to the offset field in the structure's documentation.

Affected products

Linux
  • <a554dfcd30dd5e41d1d67387b3bb85cea83e12e1
  • <7.0
  • ==28f488e7b327630686378bb1d24e22cfc3fc162d
  • <a1b836607304f71051f9f9dcccf8b5097b86a1fb
  • =<7.0.*
  • =<*
  • <6.20
  • ==7.0