tree c218d8543fe5c6f2655204bfb8d01061e6d25553
parent 628950379a02a2956ba8a1beeaa18a718922092a
author Jan Beulich <jbeulich@suse.com> 1656662239 +0200
committer Meena Shanmugam <meenashanmugam@google.com> 1657943631 +0000

xen-netfront: restore __skb_queue_tail() positioning in xennet_get_responses()

commit f63c2c2032c2e3caad9add3b82cc6e91c376fd26 upstream.

The commit referenced below moved the invocation past the "next" label,
without any explanation. In fact this allows misbehaving backends undue
control over the domain the frontend runs in, as earlier detected errors
require the skb to not be freed (it may be retained for later processing
via xennet_move_rx_slot(), or it may simply be unsafe to have it freed).

This is CVE-2022-33743 / XSA-405.

BUG=b/239161485
TEST=presubmit, validation
RELEASE_NOTE=Fixed CVE-2022-33743 in the Linux kernel.

Fixes: 6c5aa6fc4def ("xen networking: add basic XDP support for xen-netfront")
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

cos-patch: security-moderate
Change-Id: Ic36c823acafbcd2a1630784b966db1e6f9838981
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/34831
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Reviewed-by: Oleksandr Tymoshenko <ovt@google.com>
