F5-K000148931: High severity f5 traffix systems signaling delivery controller vulnerability
In the Linux kernel, the following vulnerability has been resolved: afunix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embryo has a peer that carries SCMRIGHTS, two consecutive passes of scanchildren() may see a different set of children. Leading to an incorrectly elevated inflight count, and then a dangling pointer within the gcinflightlist. sockets are AFUNIX/SOCKSTREAM S is an unconnected socket L is a listening in-flight socket bound to addr, not in fdtable V's fd will be passed via sendmsg(), gets inflight count bumped connect(S, addr) sendmsg(S, [V]); close(V) unixgc() ---------------- ------------------------- ----------- NS = unixcreate1() skb1 = sockwmalloc(NS) L = unixfindother(addr) unixstatelock(L) unixpeer(S) = NS // V count=1 inflight=0 NS = unixpeer(S) skb2 = sockalloc() skbqueuetail(NS, skb2[V]) // V became in-flight // V count=2 inflight=1 close(V) // V count=1 inflight=1 // GC candidate condition met for u in gcinflightlist: if (totalrefs == inflightrefs) add u to gccandidates // gccandidates={L, V} for u in gccandidates: scanchildren(u, decinflight) // embryo (skb1) was not // reachable from L yet, so V's // inflight remains unchanged skbqueuetail(L, skb1) unixstateunlock(L) for u in gccandidates: if (u.inflight) scanchildren(u, incinflightmovetail) // V count=1 inflight=2 (!) If there is a GC-candidate listening socket, lock/unlock its state. This makes GC wait until the end of any ongoing connect() to that socket. After flipping the lock, a possibly SCM-laden embryo is already enqueued. And if there is another embryo coming, it can not possibly carry SCMRIGHTS. At this point, unixinflight() can not happen because unixgclock is already taken. Inflight graph remains unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000148931?
The severity of F5-K000148931 is considered high due to the potential for exploitation related to improper garbage collection in the Linux kernel.
How do I fix F5-K000148931?
To fix F5-K000148931, upgrade the affected software to the latest version provided by F5.
What systems are affected by F5-K000148931?
F5-K000148931 specifically affects the F5 Traffix Systems Signaling Delivery Controller version 5.2.0.
What symptoms might indicate exposure to F5-K000148931?
Symptoms of exposure to F5-K000148931 could include unexpected behavior in Unix socket connections and potential service disruptions.
Is there a workaround for F5-K000148931?
There are no known workarounds for F5-K000148931; the recommended action is to apply the security patch.