From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B627541735B; Tue, 21 Jul 2026 19:58:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784663888; cv=none; b=LcsYEbreS7IwtE4OX16IO+i/Moa9kxTqc2vpWGWLO6oAtyls1lMW78KgGY/rmDdbrlNFrSAOY88Eg/BsNyOmn+3nERFc66UhrCB/XVqKfocSm/bQyLLp/FsDkPdZdSw3rBOLpnl+w4CpEhRt9yFYPpuXMjKWNFU1JwROZ3sgock= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784663888; c=relaxed/simple; bh=VBuRd+4ygXSTrRII0W+Hl1U8Nq5c8JXkblOMu4R5WZc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kUMkyVerLeSpZg4hG/QXzrYq1bhkEUKXYVqBeMQHOywpyC6dUw4aDE22mJa8UDiy1Rz9idsMf+9UQ/OCBXXMUYqNY/FJsRAKCSVEWjpTCPNL+WfUglMt5EEPp4loep3JhOxIX2dJ06DLBU3TspesiBRfZ3iRu7FRM/8IZQczaI4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=eTS5XEQK; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="eTS5XEQK" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A59DE1F000E9; Tue, 21 Jul 2026 19:58:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784663885; bh=r/3/VMC1Hn2GfxA1phjdnNEqAozb4BrcERqsAAqb0gs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=eTS5XEQKAyE53LnpB3T8VT/TUIrXXGmAkSf3i69oL/AcL+vinLZGt1DvnjkmXi8Op 7CH6ZnPU/nUOxNBlVUknmycbzgigw35QPyxVUtYt+ACoMsB9ZTwUX/MBIPQ8vnmB59 RRVi92lD4ARP3FDm80CjDwP+q0mvwihAcybhc7io= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Nico Yip , Oliver Hartkopp , stable@kernel.org, Marc Kleine-Budde Subject: [PATCH 6.12 0992/1276] can: isotp: use unconditional synchronize_rcu() in isotp_release() Date: Tue, 21 Jul 2026 17:23:55 +0200 Message-ID: <20260721152508.211371267@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260721152446.065700225@linuxfoundation.org> References: <20260721152446.065700225@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Oliver Hartkopp commit 9b1a02e0d980ac6b0e36a90378f847062f81d7e4 upstream. isotp_notify() unregisters the (RCU) CAN filters via can_rx_unregister() and clears so->bound without waiting for a grace period. isotp_release() uses so->bound to decide whether it needs to call synchronize_rcu() before cancelling so->rxtimer, so when NETDEV_UNREGISTER runs first it skips that synchronize_rcu() and can cancel the timer while an in-flight isotp_rcv() is still executing and about to re-arm it via isotp_send_fc(), leading to a use-after-free timer callback on the freed socket. sakisho-bot remarked a problem with rtnl_lock held in isotp_notify(), therefore make isotp_release() always call synchronize_rcu() before cancelling the timers, regardless of so->bound. This still closes the original race (isotp_notify() clearing so->bound without waiting for in-flight isotp_rcv() callers before isotp_release() cancels the RX timer) without adding any RCU wait to the netdevice notifier path. Fixes: 14a4696bc311 ("can: isotp: isotp_release(): omit unintended hrtimer restart on socket release") Closes: https://lore.kernel.org/linux-can/20260707085210.6B6C01F000E9@smtp.kernel.org/ Reported-by: Nico Yip Signed-off-by: Oliver Hartkopp Link: https://patch.msgid.link/20260712-isotp-fixes-v10-1-793a1b1ce17f@hartkopp.net Cc: stable@kernel.org Signed-off-by: Marc Kleine-Budde Signed-off-by: Greg Kroah-Hartman --- net/can/isotp.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) --- a/net/can/isotp.c +++ b/net/can/isotp.c @@ -1217,11 +1217,18 @@ static int isotp_release(struct socket * SINGLE_MASK(so->txid), isotp_rcv_echo, sk); dev_put(dev); - synchronize_rcu(); } } } + /* Always wait for a grace period before touching the timers below. + * A concurrent NETDEV_UNREGISTER may have already unregistered our + * filters and cleared so->bound in isotp_notify() without waiting + * for in-flight isotp_rcv() callers to finish, so this call must not + * be skipped just because so->bound is already 0 here. + */ + synchronize_rcu(); + hrtimer_cancel(&so->txfrtimer); hrtimer_cancel(&so->txtimer); hrtimer_cancel(&so->rxtimer);