Received: by 2002:a05:6358:111d:b0:dc:6189:e246 with SMTP id f29csp152139rwi; Wed, 2 Nov 2022 10:18:39 -0700 (PDT) X-Google-Smtp-Source: AMsMyM59ccTKJA2X/2RUIuUr91Mb7mZiokQNwW8e4hJHceHKR63Zw7fJ6A/k465LOxcIA9cnuby1 X-Received: by 2002:a05:6402:5248:b0:461:f0fa:864e with SMTP id t8-20020a056402524800b00461f0fa864emr25231167edd.81.1667409519570; Wed, 02 Nov 2022 10:18:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1667409519; cv=none; d=google.com; s=arc-20160816; b=WM/viC7gYoEOtO1oBA1htG+vJTslcA7InCJMrsGKMFAX9k2T8W9al0DV5Gp0o0/J/X 2fbgFuSYhObzntPzK14B4kh8Idtnbj+sYWhsi6wkcjKzbn92h2lkswbxqEuA0UB1hQni B7TD7e19eNiLM/Gexubk63TYWBPG+VhGkfI2vwYMan3mD4JuHQmP2+TR7trLv+oC70WF yOH2B06v4mEBFlRLPA0r4zB0dUd5i/IpBztQWVIZ9mSoQgjo7s8Bp/iV0iy71iqLpU1T NkRxyEaK/K5LFHy8nteKM7cikP6k8se9GGbSJPtjI1YSVjmgfFI+wJsRO9z9iGvGHTd5 ntFw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=g3FwrdOXirpvuI71plfb4en5QdORvGmwK8vjtjrbqCY=; b=WUI7iDK4RL8F4TMhb/Sdp5pypSigidrPppB2PPcCdp7d9IfHsX6qHX1NkdqXdjPi4k NbspF+eRGA3PPxV0ORNgZyxZ937fmlRDfTRY+HdjlLhDGzuHGyvRTn0oxRAWLdLqiu0+ iaSz6AcYFK7eKmfXkcSNn/vaCTszPltyz08xhYaf3xpcK1u9KBUNryqrP4Y2PNUjKbjq U/mVExXZkHv61jETspn93ZQtAD093QFEbPneCgKI9sbreu5H/thFfw4Rte9/bFz4diBH IaQgytkemXFXo8Lngm6piTWnROdYfYTYc56BsYIqx00FZIIt0qYdqxiafPeaB1H27D7q SHQA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=aZurwhW5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id my15-20020a1709065a4f00b00781cde43588si13070953ejc.58.2022.11.02.10.18.15; Wed, 02 Nov 2022 10:18:39 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=aZurwhW5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230186AbiKBRMU (ORCPT + 98 others); Wed, 2 Nov 2022 13:12:20 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37602 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231628AbiKBRLk (ORCPT ); Wed, 2 Nov 2022 13:11:40 -0400 Received: from mail-pg1-x532.google.com (mail-pg1-x532.google.com [IPv6:2607:f8b0:4864:20::532]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 4A01E1A04C; Wed, 2 Nov 2022 10:11:39 -0700 (PDT) Received: by mail-pg1-x532.google.com with SMTP id q1so16753666pgl.11; Wed, 02 Nov 2022 10:11:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=g3FwrdOXirpvuI71plfb4en5QdORvGmwK8vjtjrbqCY=; b=aZurwhW5CjSNzRBZFaCtmB1HgWHbhp0eR6jNQW/ObU2vasTqsskyUE45GOd9uNrFnF CaWoD33gdMXaB+Z6MTfO+Sqt17DiPuiPP9hwFwdfY4iNa7prRVNAfyRg6mfljD+LU0pe V95Jc6FYjucId3PktJyRnmKFLP/EwaVsQv/G9s9xF6fld9czdVJuKBjlnVeRjF0t9JaZ 9gHUw6Ohv5kU93xsjvOzTXWKzsW4VUWKvnaNYy6sU91glzdAONT10RNlXqZXNL48wgbU mOU97X9WoR+c74+TTD1JRWKtxdyNw5EEEFXtt/T7iH+8EgP9C5ygybqRA+ONza0Gmcwp RQ+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=g3FwrdOXirpvuI71plfb4en5QdORvGmwK8vjtjrbqCY=; b=TlvMHP0U8RAu/Xfbf7Clvg5bxJ9We+vrjIhLd+XQ03eUKoXHhSQeIPkVmC0ABOQV3p ZGk6e26VHvyBnviw+Uvgw5Eze49FJEbNuaw/VYb+FD0iBW/FvajzAFD8+rNropBsAEZE q9i9ZyqRvqgdlldHAVsVSPD+KoIu2VMr8jJJUTR1bW6FzhZkaGJizA/c2Awvleu/17RG coOaXV916SU/6+UHQX08YPA/jFNVaikJmv9RzCAKPAaRO0teJDpZhOsfobe0Ubn0VlGG KwQvnGh/t+qVOyJ3QqpLGtDWFHbjmXp1zEBh9AzQMKsn1DE1m/WoOYSg95kCEZjQHxlg qUGA== X-Gm-Message-State: ACrzQf24M0IlWpJLWxzuv5RSpUgFWOgh/Kj15ebDCp7BmmRo0A/+Fe84 gOlXRbgd/kRD/IbzkpgvAI8= X-Received: by 2002:a62:5486:0:b0:56e:3a98:dcc with SMTP id i128-20020a625486000000b0056e3a980dccmr400740pfb.63.1667409098797; Wed, 02 Nov 2022 10:11:38 -0700 (PDT) Received: from ubuntu ([175.124.254.119]) by smtp.gmail.com with ESMTPSA id e11-20020a63500b000000b0042fe1914e26sm7793550pgb.37.2022.11.02.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 02 Nov 2022 10:11:38 -0700 (PDT) Date: Wed, 2 Nov 2022 10:11:34 -0700 From: Hyunwoo Kim To: Mauro Carvalho Chehab Cc: Takashi Iwai , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, imv4bel@gmail.com Subject: Re: [PATCH RE-SEND] media: dvb-core: Fix UAF due to refcount races at releasing Message-ID: <20221102171134.GA491335@ubuntu> References: <20221031100245.23702-1-tiwai@suse.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20221031100245.23702-1-tiwai@suse.de> X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Dear media people, This CVE-2022-41218 has been a long time since the vulnerability details and PoC code were released: https://www.openwall.com/lists/oss-security/2022/09/24/1 However, many distros are still vulnerable to this issue. If you don't mind, could you please tell me the progress of this patch? Best Regards, Hyunwoo Kim.