The University of Minnesota has been suspended from development of the Linux kernel for sending questionable patches.

Greg Kroah-Hartman, responsible for maintaining the stable branch of the Linux kernel, has decided to ban any changes from the University of Minnesota from being accepted into the Linux kernel, as well as to roll back all previously accepted patches and conduct a re-review of them. The reason for the block was the activities of a research group studying the potential promotion of hidden vulnerabilities in the code of open-source projects. This group submitted patches that included various bugs, observed the community's reaction, and explored ways to deceive the change review process. Greg believes that conducting such experiments to introduce malicious changes is unacceptable and unethical.

The block was prompted by the submission of a patch by members of this group, which added a pointer check to prevent possible double calls to the 'free' function. Given the pointer's context, the check was meaningless. The goal of submitting the patch was to study whether the erroneous change would pass the kernel developers' review. In addition to this particular patch, other attempts by developers from the University of Minnesota to introduce questionable changes to the kernel emerged, including those related to adding hidden vulnerabilities.

The participant who submitted the patches attempted to justify himself by claiming he was testing a new static analyzer and that the change was based on the check results from it. However, Greg pointed out that the proposed fixes are not typical of the errors identified by static analyzers, and all the submitted patches do not actually fix anything at all. Taking into account that the mentioned group of researchers has previously attempted to promote fixes with hidden vulnerabilities, it is obvious that they have continued their experiments on the kernel development community.

Interestingly, the leader of the group conducting the experiments previously participated in legitimate vulnerability remediation, for example, identifying information leaks in the USB stack (CVE-2016-4482) and network subsystem (CVE-2016-4485). In the study of hidden vulnerability promotion, a group from the University of Minnesota cites the example of vulnerability CVE-2019-12819, caused by a fix adopted into the kernel in 2014. The fix added a call to put_device in the error handling block of mdio_bus, but five years later, it emerged that such manipulation leads to accessing a memory block after it has been freed ("use-after-free").

At the same time, the authors of the study claim that they summarized data on 138 patches introducing errors that are not related to the participants of the study. Attempts to submit one's own erroneous patches were limited to email correspondence, and such changes did not make it into Git (if after sending a patch via email the maintainer considered the patch acceptable, they were asked not to include the change since there was an error, after which the correct patch was sent).

Supplement 1: Judging by the activity of the author of the criticized fix, he has been sending patches to various subsystems of the kernel for a long time. For example, recent changes in the radeon and nouveau drivers included a call to pm_runtime_put_autosuspend(dev->dev) in the error block, which may lead to using a buffer after the associated memory has been freed.

Supplement 2: Greg reverted 190 commits associated with addresses "@umn.edu" and initiated their re-review. The problem is that participants with "@umn.edu" addresses not only experimented with promoting dubious patches but also addressed real vulnerabilities, and reverting changes could lead to a return of previously fixed security issues. Some maintainers have already rechecked the canceled changes and found no problems, but one maintainer noted that there were errors in one of the patches sent to him.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster