nluedtke / linux_kernel_cves

Tracking CVEs for the linux Kernel
Apache License 2.0
739 stars 71 forks source link

[DATA] CVE-2021-28951 is likely >= 5.10 #291

Closed DerDakon closed 1 year ago

DerDakon commented 2 years ago

Change Type Requested Update

CVE id number CVE-2021-28951

References https://github.com/torvalds/linux/commit/7e84e1c7566a1df470a9e1f49d3db2ce311261a4

Additional context The fixes commit (https://github.com/torvalds/linux/commit/3ebba796fa251d042be42b929a2d916ee5c34a49) talks about the deadlock happening because of IORING_SETUP_R_DISABLED, which was only introduced for 5.10. Since all backports happened to 5.10.x and newer versions, but no older ones, I assume this commit is indeed the culprit and should be used for "breaks".

nluedtke commented 1 year ago

fixed in 4a25de649358f157abb6737f013f9baa7f66e6f8