In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in...
Low severity
Unreviewed
Published
Apr 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 7, 2019
Published to the GitHub Advisory Database
Apr 21, 2022
Last updated
Jan 27, 2023
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that "current" references work. Without this, "current" used in the window between iret_exc and the middle of error_code where %fs is reset, would crash.
References