CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's RXRPC implementation, specifically in the handling of the `rx_dec_buffer` during message reception. If the buffer is unallocated and the length is zero, it can lead to a NULL pointer dereference when attempting to copy data, potentially causing application crashes or denial of service. Organizations using Linux systems that rely on RXRPC should prioritize this fix to maintain system stability and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc rxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the rxrpc_call.rx_dec_buffer is unallocated and assumes that upon successful return that rx_dec_buffer must be allocated. However, rxrpc_verify_data() does not request an allocation if the rxrpc_skb_priv.len is zero. In addition, failure to allocate rx_dec_buffer will result in a call to skb_copy_bits() with a NULL destination which can trigger a NULL pointer dereference. To prevent these issues rxrpc_verify_data() is modified to always attempt to allocate the rxrpc_call.rx_dec_buffer if it is NULL. This issue was identified with assistance of a private sashiko instance.