From: Simon Horman <horms@kernel.org>
To: Chengfeng Ye <nicoyip.dev@gmail.com>
Cc: "David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Thorsten Blum <thorsten.blum@linux.dev>,
Andrew Morton <akpm@linux-foundation.org>,
Andy Shevchenko <andriy.shevchenko@intel.com>,
Randy Dunlap <rdunlap@infradead.org>,
Robert Olsson <robert.olsson@its.uu.se>,
Stephen Hemminger <stephen@networkplumber.org>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: Re: [PATCH] net: pktgen: fix proc entry use-after-free
Date: Fri, 24 Jul 2026 14:24:48 +0100 [thread overview]
Message-ID: <20260724132448.GK418547@horms.kernel.org> (raw)
In-Reply-To: <20260719145740.2888967-1-nicoyip.dev@gmail.com>
On Sun, Jul 19, 2026 at 10:57:40PM +0800, Chengfeng Ye wrote:
> pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock.
> pktgen_remove_device() removes the same entry before
> _rem_dev_from_if_list() takes that lock.
>
> This allows the following interleaving:
>
> CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend)
> if_lock(t)
> proc_remove(pkt_dev->entry)
> proc_remove(pkt_dev->entry)
> pkt_dev->entry = proc_create_data(...)
> if_unlock(t)
>
> The kthread can pass the stale proc_dir_entry to proc_remove() after the
> rename path has freed it. A reproducer with a widened race window reports:
>
> BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80
> Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67
> Call Trace:
> proc_remove+0x78/0x80
> pktgen_remove_device.isra.0+0x11c/0x4c0
> pktgen_thread_worker+0x1214/0x6bc0
> kthread+0x2c6/0x3b0
> Allocated by task 95:
> __proc_create+0x204/0x790
> proc_create_data+0x72/0xe0
> pktgen_thread_write+0xd61/0x1510
> Freed by task 28:
> kmem_cache_free+0xcb/0x3d0
> proc_free_inode+0x5b/0x80
> rcu_core+0x50a/0x1850
> The buggy address belongs to the object at ffff8881478fea00
> which belongs to the cache proc_dir_entry of size 192
>
> Move proc_remove() into the if_lock-protected list removal helper. Keep it
> before list_del_rcu() to preserve the ordering required by add_device().
> The rename path must then finish replacing the entry before removal, or
> it observes that the device is no longer on the list.
>
> Fixes: 39df232f1a9b ("[PKTGEN]: fix device name handling")
> Cc: stable@vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
next prev parent reply other threads:[~2026-07-24 13:24 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-19 14:57 [PATCH] net: pktgen: fix proc entry use-after-free Chengfeng Ye
2026-07-24 13:24 ` Simon Horman [this message]
2026-07-24 23:40 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260724132448.GK418547@horms.kernel.org \
--to=horms@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=andriy.shevchenko@intel.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=nicoyip.dev@gmail.com \
--cc=pabeni@redhat.com \
--cc=rdunlap@infradead.org \
--cc=robert.olsson@its.uu.se \
--cc=stable@vger.kernel.org \
--cc=stephen@networkplumber.org \
--cc=thorsten.blum@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.