Re: CVE-2021-47469: spi: Fix deadlock when adding SPI controllers on SPI buses

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, Mar 02, 2025 at 07:03:30PM +0100, Ben Hutchings wrote:
> Hi all,
> 
> CVE-2021-47469 is supposed to be fixed by commit 6098475d4cb4 "spi: Fix
> deadlock when adding SPI controllers on SPI buses" but I think this
> assignment should be rejected.
> 
> The commit fixes a deadlock during addition of an SPI device.  Since SPI
> does not support auto-discovery, I think that adding such a device
> requires CAP_SYS_ADMIN privilege (but I'm not certain).
> 
> Since it is intended that a user with CAP_SYS_ADMIN can deny service
> through the reboot system call, I don't think additional ways to do this
> are security flaws.

Now rejected, thanks.

greg k-h




[Index of Archives]     [Linux Kernel]     [Linux ARM (vger)]     [Linux ARM MSM]     [Linux Omap]     [Linux Arm]     [Linux Tegra]     [Fedora ARM]     [Linux for Samsung SOC]     [eCos]     [Linux Fastboot]     [Gcc Help]     [Git]     [DCCP]     [IETF Announce]     [Security]     [Linux MIPS]     [Yosemite Campsites]

  Powered by Linux