CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem, where a busy-wait loop in the `tipc_exit_net()` function can lead to excessive CPU cycle consumption and potential soft lockups, particularly under high-priority task execution or non-preemptive kernel configurations. This issue should be prioritized by system administrators and developers managing Linux environments, especially those utilizing TIPC, to ensure system stability and prevent performance degradation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete: while (atomic_read(&tn->wq_count)) cond_resched(); This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups. Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero. Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero. This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.