From: Heiko Carstens <hca@linux.ibm.com>
To: Nagamani PV <nagamani@linux.ibm.com>
Cc: wintera@linux.ibm.com, aswin@linux.ibm.com,
sidraya@linux.ibm.com, hidayath@linux.ibm.com,
pasic@linux.ibm.com, mjambigi@linux.ibm.com, dk@linux.ibm.com,
twinkler@linux.ibm.com, jaka@linux.ibm.com, wenjia@linux.ibm.com,
gbayer@linux.ibm.com,
linux390-list@tuxmaker.boeblingen.de.ibm.com,
stable@vger.kernel.org,
syzbotz+89435e7383b82238dd91@linux.ibm.com
Subject: Re: [PATCH] net/iucv: fix UAF in afiucv_netdev_event()
Date: Mon, 11 May 2026 11:02:34 +0200 [thread overview]
Message-ID: <20260511090234.9589A54-hca@linux.ibm.com> (raw)
In-Reply-To: <20260508163836.2207648-1-nagamani@linux.ibm.com>
On Fri, May 08, 2026 at 06:38:36PM +0200, Nagamani PV wrote:
> afiucv_netdev_event() traverses iucv_sk_list without holding
> iucv_sk_list.lock.
>
> A concurrent socket teardown can unlink and free the socket via
> iucv_sock_kill() while the notifier path is still iterating over
> the list, leading to a possible use-after-free when dereferencing
> the socket.
>
> Protect the traversal using the existing read-side lock, matching
> the locking pattern already used by other iucv_sk_list traversal
> paths in af_iucv.c.
>
> Use read_lock()/read_unlock() to remain consistent with existing
> softirq/tasklet-side readers in the same file.
>
> Fixes: 9fbd87d41392 ("af_iucv: handle netdev events")
> Cc: stable@vger.kernel.org
> Reported-by: syzbotz+89435e7383b82238dd91@linux.ibm.com
> Closes: https://lnxgwne1.boeblingen.de.ibm.com/linux-ci/syzbot/dashboard/bug?extid=89435e7383b82238dd91
Please don't add IBM internal references to commit messages. They are
useless, besides that they will go away rather sooner than later. Better:
add the _relevant_ parts of the crash output to the commit message, which
allows people to make verify if this patch is actually fixing what the
commit message says.
> diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
> index 72dfccd4e3d5..e8a0b55fc55d 100644
> --- a/net/iucv/af_iucv.c
> +++ b/net/iucv/af_iucv.c
> @@ -2188,6 +2188,7 @@ static int afiucv_netdev_event(struct notifier_block *this,
> switch (event) {
> case NETDEV_REBOOT:
> case NETDEV_GOING_DOWN:
> + read_lock(&iucv_sk_list.lock);
> sk_for_each(sk, &iucv_sk_list.head) {
> iucv = iucv_sk(sk);
> if ((iucv->hs_dev == event_dev) &&
Are you sure that afiucv_netdev_event() is called in either tasklet context
or with bottom halves disabled? Doesn't look like it to me.
Read: most likely this should be read_lock_bh() to avoid deadlocks.
But then again I might be completely wrong, and lockdep says that this code
is actually correct :)
next prev parent reply other threads:[~2026-05-11 9:02 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-08 16:38 [PATCH] net/iucv: fix UAF in afiucv_netdev_event() Nagamani PV
2026-05-11 9:02 ` Heiko Carstens [this message]
2026-05-11 12:46 ` Nagamani PV
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260511090234.9589A54-hca@linux.ibm.com \
--to=hca@linux.ibm.com \
--cc=aswin@linux.ibm.com \
--cc=dk@linux.ibm.com \
--cc=gbayer@linux.ibm.com \
--cc=hidayath@linux.ibm.com \
--cc=jaka@linux.ibm.com \
--cc=linux390-list@tuxmaker.boeblingen.de.ibm.com \
--cc=mjambigi@linux.ibm.com \
--cc=nagamani@linux.ibm.com \
--cc=pasic@linux.ibm.com \
--cc=sidraya@linux.ibm.com \
--cc=stable@vger.kernel.org \
--cc=syzbotz+89435e7383b82238dd91@linux.ibm.com \
--cc=twinkler@linux.ibm.com \
--cc=wenjia@linux.ibm.com \
--cc=wintera@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.