1. Over two years ago, this was apparently detected automatically by the syzkaller kernel fuzzer, and automatically reported on its public mailing list. [1]
2. Over a year and a half ago, it was apparently fixed in the upstream kernel. [2]
3. It was apparently never merged back to various "stable" kernels, leading to the recent CVE. [3]
So you might read that and think "Ok, probably a rare mistake"...
...but instead:
4. This is apparently a _super_ common sequence of events, with kernel vulnerabilities getting lost in the shuffle, or otherwise not backported to "stable" kernels for a variety of reasons like the patch no cleanly longer applies.
Dmitry Vyukov (original author of syzkaller fuzzer that found this 2 years ago) gave a very interesting talk on how frequently this happens a couple weeks ago at the Linux Maintainer's Summit, along with some discussion of how to change kernel dev processes to try to dramatically improve things:
slides: https://linuxplumbersconf.org/event/4/contributions/554/atta...
video: https://youtu.be/a2Nv-KJyqPk?t=5239
---
[1] https://twitter.com/dvyukov/status/1180195777680986113
[2] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux...
[3] https://mobile.twitter.com/grsecurity/status/118005953923380...