In the Linux kernel, the following vulnerability has been resolved:
io_uring/poll: don't reissue in case of poll race on multishot request
A previous commit fixed a poll race that can occur, but it's only
applicable for multishot requests. For a multishot request, we can safely
ignore a spurious wakeup, as we never leave the waitqueue to begin with.
A blunt reissue of a multishot armed request can cause us to leak a
buffer, if they are ring provided. While this seems like a bug in itself,
it's not really defined behavior to reissue a multishot request directly.
It's less efficient to do so as well, and not required to rearm anything
like it is for singleshot poll requests.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2024-08-21 07:15
Updated : 2024-09-11 16:31
NVD link : CVE-2023-52895
Mitre link : CVE-2023-52895
CVE.ORG link : CVE-2023-52895
JSON object : View
Products Affected
                linux
- linux_kernel
CWE
                
                    
                        
                        CWE-401
                        
            Missing Release of Memory after Effective Lifetime
