Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 day, 7 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
igc: remove napi_synchronize() in igc_down()

In the Linux kernel, the following vulnerability has been resolved: igc: remove napi_synchronize() in igc_down() When an AF_XDP zero-copy application is killed abruptly, the XSK pool is torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the full budget on every poll, so napi_complete_done() never clears NAPI_STATE_SCHED. igc_down() calls napi_synchronize() before napi_disable(), so it spins forever waiting for that bit and the interface never goes down. Drop the napi_synchronize() and let napi_disable() do the job -- it sets NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after polling has stopped, matching the recent igb fix b1e067240379.

Affected products

Linux
  • <5.14
  • =<6.1.*
  • =<6.18.*
  • <605585a8d89aaeb0122e9016fdaa92376897a705
  • <ad6e0df267dc96edb7de1fa0a2fb2a70645bff86
  • <9a2b637aef4e515c2179774888441d00e8a5ae95
  • =<6.6.*
  • <a0f16c337691813f8d8f014c01fff5a368e08898
  • =<6.12.*
  • =<7.1.*
  • <3b5aee6fcbf6b58112d40d19c8d31fa3f78ee668
  • <f929a6fe5b7ae1e72d2c6d18cd69ab90dcf689d2
  • =<5.15.*
  • <5ffab5b9589c50e4cfc0cf36ffd76c89422d4019
  • ==5.14
  • =<*