From: David Howells <dhowells@redhat.com>
To: netdev@vger.kernel.org
Cc: David Howells <dhowells@redhat.com>,
Marc Dionne <marc.dionne@auristor.com>,
Jakub Kicinski <kuba@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Paolo Abeni <pabeni@redhat.com>, Simon Horman <horms@kernel.org>,
linux-afs@lists.infradead.org, linux-kernel@vger.kernel.org,
Jeffrey Altman <jaltman@auristor.com>,
stable@kernel.org
Subject: [PATCH net v3 09/14] afs: Fix UAF in afs_make_call()
Date: Mon, 13 Jul 2026 09:10:15 +0100 [thread overview]
Message-ID: <20260713081022.2186481-10-dhowells@redhat.com> (raw)
In-Reply-To: <20260713081022.2186481-1-dhowells@redhat.com>
There's a potential UAF in afs_make_call() in the event that an
asynchronous call is being sent, but the call fails in some way (e.g. it
gets aborted from the server). The problem is that afs_make_call() tries
to abort a call if the rxrpc send fails, but the asynchronous notification
from rxrpc may have caused the afs_call to be torn down.
Fix this making afs_make_op_call() give the op->call its own ref rather
than transferring the caller's ref to it and then dropping the ref when
afs_make_call() returns.
This also means that the afs_make_call() func never loses its ref on the
call now.
Fixes: e49c7b2f6de7 ("afs: Build an abstraction around an "operation" concept")
Link: https://sashiko.dev/#/patchset/20260702144919.172295-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Eric Dumazet <edumazet@google.com>
cc: "David S. Miller" <davem@davemloft.net>
cc: Jakub Kicinski <kuba@kernel.org>
cc: Paolo Abeni <pabeni@redhat.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
---
fs/afs/internal.h | 3 ++-
fs/afs/rxrpc.c | 3 ---
include/trace/events/afs.h | 2 ++
3 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/fs/afs/internal.h b/fs/afs/internal.h
index 4901d0acbe14..645fe2f12dc5 100644
--- a/fs/afs/internal.h
+++ b/fs/afs/internal.h
@@ -1417,7 +1417,7 @@ static inline void afs_make_op_call(struct afs_operation *op, struct afs_call *c
{
struct afs_addr_list *alist = op->estate->addresses;
- op->call = call;
+ op->call = afs_get_call(call, afs_call_trace_get_op_call);
op->type = call->type;
call->op = op;
call->key = op->key;
@@ -1425,6 +1425,7 @@ static inline void afs_make_op_call(struct afs_operation *op, struct afs_call *c
call->peer = rxrpc_kernel_get_peer(alist->addrs[op->addr_index].peer);
call->service_id = op->server->service_id;
afs_make_call(call, gfp);
+ afs_put_call(call, afs_call_trace_put_made_call);
}
static inline void afs_extract_begin(struct afs_call *call, void *buf, size_t size)
diff --git a/fs/afs/rxrpc.c b/fs/afs/rxrpc.c
index a1b9ced4e0f4..6dc6fd853832 100644
--- a/fs/afs/rxrpc.c
+++ b/fs/afs/rxrpc.c
@@ -382,8 +382,6 @@ void afs_make_call(struct afs_call *call, gfp_t gfp)
if (ret < 0)
goto error_do_abort;
- /* We lost our ref on call if MSG_MORE was not set and ret >= 0. */
-
if (write_iter) {
msg.msg_iter = *call->write_iter;
msg.msg_flags &= ~MSG_MORE;
@@ -393,7 +391,6 @@ void afs_make_call(struct afs_call *call, gfp_t gfp)
call->rxcall, &msg,
iov_iter_count(&msg.msg_iter),
afs_notify_end_request_tx);
- /* We lost our ref on call if ret >= 0. */
trace_afs_sent_data(debug_id, &msg, ret);
if (ret < 0)
diff --git a/include/trace/events/afs.h b/include/trace/events/afs.h
index df397c11df85..a1963e21f034 100644
--- a/include/trace/events/afs.h
+++ b/include/trace/events/afs.h
@@ -122,8 +122,10 @@ enum yfs_cm_operation {
#define afs_call_traces \
EM(afs_call_trace_alloc, "ALLOC ") \
EM(afs_call_trace_free, "FREE ") \
+ EM(afs_call_trace_get_op_call, "GET op ") \
EM(afs_call_trace_get_make_async_call, "GET a-make ") \
EM(afs_call_trace_put_async_complete, "PUT a-cmpl ") \
+ EM(afs_call_trace_put_made_call, "PUT made ") \
EM(afs_call_trace_put_discard_prealloc, "PUT dis-pre") \
EM(afs_call_trace_put_get_capabilities, "PUT get-cap") \
EM(afs_call_trace_put_giveupcallbacks, "PUT gvup-cb") \
next prev parent reply other threads:[~2026-07-13 8:11 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-13 8:10 [PATCH net v3 00/14] rxrpc: Fix CHALLENGE packet handling David Howells
2026-07-13 8:10 ` [PATCH net v3 01/14] rxrpc: Fix sendmsg to not return an error if last packet queued David Howells
2026-07-13 8:10 ` [PATCH net v3 02/14] afs: Fix UAF when sending a message David Howells
2026-07-13 8:10 ` [PATCH net v3 03/14] afs: Fix afs_fs_fetch_data() to set call->async David Howells
2026-07-13 8:10 ` [PATCH net v3 04/14] rxrpc: Fix packet encryption error handling David Howells
2026-07-20 14:52 ` Simon Horman
2026-07-13 8:10 ` [PATCH net v3 05/14] rxrpc: Fix update of call->tx_pending without holding lock David Howells
2026-07-13 8:10 ` [PATCH net v3 06/14] rxrpc: Fix generation of notifications after call completion David Howells
2026-07-13 8:10 ` [PATCH net v3 07/14] afs: Simplify call refcounting David Howells
2026-07-20 14:52 ` Simon Horman
2026-07-13 8:10 ` [PATCH net v3 08/14] afs: Make afs_put_call() take trace argument David Howells
2026-07-13 8:10 ` David Howells [this message]
2026-07-13 8:10 ` [PATCH net v3 10/14] keys: Add refcounting to user-defined key type payload David Howells
2026-07-13 8:10 ` [PATCH net v3 11/14] afs: Create a server appdata key David Howells
2026-07-20 14:53 ` Simon Horman
2026-07-13 8:10 ` [PATCH net v3 12/14] rxrpc: Pass appdata key to rxrpc_call and thence to rxrpc_bundle David Howells
2026-07-20 14:54 ` Simon Horman
2026-07-13 8:10 ` [PATCH net v3 13/14] rxrpc: Fix CHALLENGE packet overqueuing and simplify RESPONSE generation David Howells
2026-07-20 14:54 ` Simon Horman
2026-07-13 8:10 ` [PATCH net v3 14/14] rxrpc: Remove OOB challenge/response code David Howells
2026-07-20 14:56 ` Simon Horman
2026-07-21 22:28 ` [PATCH net v3 00/14] rxrpc: Fix CHALLENGE packet handling Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260713081022.2186481-10-dhowells@redhat.com \
--to=dhowells@redhat.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jaltman@auristor.com \
--cc=kuba@kernel.org \
--cc=linux-afs@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marc.dionne@auristor.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.