Executive brief
A flaw in the Linux kernel's PowerPC VAS (Virtual Accelerator Switchboard) subsystem allows the kernel to access memory after it has been freed. An attacker with local access could trigger this defect to cause a kernel crash or potentially execute arbitrary code, disrupting system stability or gaining elevated privileges.
Technical details
This is a use-after-free vulnerability in the powerpc/64s VAS window close/deallocate code. The vulnerable component is the VAS memory context management in arch/powerpc/platforms (both powernv and pseries variants). The refcount on the memory management structure (mm) is dropped via put_vas_user_win_ref() before the coprocessor is detached via mm_context_remove_vas_window(), causing the freed memory to be accessed afterward. The fix reorders these operations so the coprocessor is detached first while the refcount is still valid. Exploitation requires local access to trigger VAS window close operations. A patch is available and has been committed to the Linux kernel.
Affected products
- Linux Linux kernel Multiple versions prior to fix (commit b4bda59b47879cce38a6ec5a01cd3cac702b5331)
Timeline
- 2023-06-07: disclosed
- 2023-07-19: patched