[Bionic][Cosmic] ipmi: Fix timer race with module unload
Bug #1799281 reported by
Manoj Iyer
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Fix Released
|
Critical
|
Canonical Kernel Team | ||
Bionic |
Fix Released
|
Critical
|
Canonical Kernel Team | ||
Cosmic |
Fix Released
|
Critical
|
Canonical Kernel Team |
Bug Description
[Impact]
If you attempt to remove and insert the ipmi_ssif module a number of times, it would result in a kernel panic. This is due to mod_timer from arming a timer that was already removed by del_timer during module unload.
[Fix]
In linux-next:
0711e8c1b457 ipmi: Fix timer race with module unload
[Test]
-- Test Case --
for i in {1..500}; do sudo modprobe -r ipmi_ssif; sleep 2s ; sudo modprobe ipmi_ssif || exit; done
----------------
After the patch was applied, no kernel panics were obsereved. Tested on Cavium ThunderX2.
[Regression Risk]
The patch was applied to bionic and tested tested on a Cavium ThunderX2 and no regressions were found. Risk of regression none.
CVE References
Changed in linux (Ubuntu): | |
status: | Incomplete → Triaged |
Changed in linux (Ubuntu Bionic): | |
status: | New → Triaged |
importance: | Undecided → Critical |
Changed in linux (Ubuntu Bionic): | |
status: | Triaged → In Progress |
Changed in linux (Ubuntu Cosmic): | |
status: | Triaged → In Progress |
Changed in linux (Ubuntu Bionic): | |
status: | In Progress → Fix Committed |
Changed in linux (Ubuntu Cosmic): | |
status: | In Progress → Fix Committed |
tags: |
added: verification-done-bionic verification-done-cosmic removed: verification-needed-bionic verification-needed-cosmic |
Changed in linux (Ubuntu): | |
status: | Triaged → Fix Released |
tags: | added: cscc |
To post a comment you must log in.
This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:
apport-collect 1799281
and then change the status of the bug to 'Confirmed'.
If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.
This change has been made by an automated script, maintained by the Ubuntu Kernel Team.