Kwifowuni yenkqubo ye-futex, ukubakho kokuphumeza ikhowudi yomsebenzisi kumxholo we-kernel yafunyanwa kwaye yapheliswa.

Ekuphunyezweni kwe-futex (i-fast userspace mutex) ifowuni yenkqubo, ukusetyenziswa kwememori ye-stack emva kokuba ikhululekile ifunyenwe kwaye yapheliswa. Oku, kwakhona, kwavumela umhlaseli ukuba enze ikhowudi yakhe kumxholo we-kernel, kunye nazo zonke iziphumo ezivela kwindawo yokhuseleko. Ukuba sesichengeni bekukwikhowudi yesiphathi semposiso.

Ukulungiswa Olu buthathaka luvele kwi-Linux mainline ngoJanuwari 28 kwaye kusuku olungaphambi kwezolo lwangena kwiikernels 5.10.12, 5.4.94, 4.19.172, 4.14.218.

Ngexesha lengxoxo yolu lungiso, kwacetyiswa ukuba obu buthathaka bukhona kuzo zonke iikernel ukusukela ngo-2008:

https://www.openwall.com/lists/oss-security/2021/01/29/3

FWIW, this commit has: Fixes: 1b7558e457ed ("futexes: fix fault handling in futex_lock_pi") and that other commit is from 2008. So probably all currently maintained Linux distros and deployments are affected, unless something else mitigated the issue in some kernel versions.

umthombo: linux.org.ru