diff options
| author | Tzung-Bi Shih <tzungbi@kernel.org> | 2026-07-07 10:18:03 +0000 |
|---|---|---|
| committer | Guenter Roeck <linux@roeck-us.net> | 2026-07-08 07:06:59 -0700 |
| commit | 7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661 (patch) | |
| tree | 4f86ace5237c477e11dc6a31b1a7806af223b7ab /tools/lib/python | |
| parent | 0be186a120a797edb28effb9359296ce4cde9a25 (diff) | |
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
When a watchdog governor is unregistered, it updates existing watchdog
devices that were using this governor by falling back to `default_gov`.
If the governor being unregistered is currently set as `default_gov`,
the `default_gov` is never cleared. This leads to 2 use-after-free
issues:
1. New watchdog devices registered after this point will inherit the
dangling `default_gov`.
2. Existing watchdog devices using the unregistered governor will have
their `wdd->gov` reassigned to the dangling `default_gov`.
Fix the UAF by clearing `default_gov` if it matches the governor being
unregistered.
Fixes: da0d12ff2b82 ("watchdog: pretimeout: add panic pretimeout governor")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://lore.kernel.org/r/20260707101803.3598173-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Diffstat (limited to 'tools/lib/python')
0 files changed, 0 insertions, 0 deletions
