From: Xuanqiang Luo <xuanqiang.luo@linux.dev>
To: linux-wpan@vger.kernel.org
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
alex.aring@gmail.com, stefan@datenfreihafen.org,
miquel.raynal@bootlin.com, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
horms@kernel.org, Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Subject: [PATCH net v1] mac802154: drain mac_wq before unregistering interfaces
Date: Fri, 28 Aug 2026 18:19:05 +0800 [thread overview]
Message-ID: <20260828101905.26865-1-xuanqiang.luo@linux.dev> (raw)
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
ieee802154_unregister_hw() unregisters the wpan netdevs before
destroying mac_wq. The RX path stores the receiving sub-interface
(sdata) in the queued MAC command descriptor without taking a
reference to the netdev.
If mac802154_rx_mac_cmd_worker() runs after the netdev has been freed,
it dereferences the stale pointer and triggers a KASAN
slab-use-after-free:
BUG: KASAN: slab-use-after-free in mac802154_rx_mac_cmd_worker+0xc0/0x498 [mac802154]
Read of size 8 at addr ffff0000c6db0ba8 by task kworker/u16:3/61
...
Call trace:
show_stack+0x20/0x38 (C)
dump_stack_lvl+0x78/0x90
print_address_description.constprop.0+0x88/0x398
print_report+0xa8/0x278
kasan_report+0xa8/0xf8
__asan_load8+0x9c/0xc0
mac802154_rx_mac_cmd_worker+0xc0/0x498 [mac802154]
process_one_work+0x334/0x8b8
...
Allocated by task 630:
kasan_save_stack+0x2c/0x58
kasan_save_track+0x20/0x40
kasan_save_alloc_info+0x40/0x58
__kasan_kmalloc+0xa0/0xb8
__kvmalloc_node_noprof+0x1e8/0x588
alloc_netdev_mqs+0x74/0x7f0
ieee802154_if_add+0xac/0x630 [mac802154]
ieee802154_register_hw+0x31c/0x3d0 [mac802154]
fakelb_add_one+0x250/0x318 [fakelb]
...
Freed by task 652:
kasan_save_stack+0x2c/0x58
kasan_save_track+0x20/0x40
kasan_save_free_info+0x4c/0x78
__kasan_slab_free+0x60/0x90
kfree+0x194/0x478
kvfree+0x44/0x60
netdev_release+0x4c/0x68
device_release+0xac/0x130
kobject_cleanup+0x84/0x248
kobject_put+0x98/0xf8
netdev_run_todo+0x3a0/0x5e0
rtnl_unlock+0x18/0x30
ieee802154_unregister_hw+0x48/0x90 [mac802154]
fakelb_remove+0xe8/0x148 [fakelb]
After killing local->tasklet, drain mac_wq before calling
ieee802154_remove_interfaces() so pending work completes before the
interfaces are unregistered. Do this without holding rtnl because scan
and beacon workers acquire it themselves.
Fixes: d021d218f6d9 ("mac802154: Handle received BEACON_REQ")
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
---
net/mac802154/main.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/mac802154/main.c b/net/mac802154/main.c
index ea1efef3572ae..dc80184d7d091 100644
--- a/net/mac802154/main.c
+++ b/net/mac802154/main.c
@@ -276,6 +276,11 @@ void ieee802154_unregister_hw(struct ieee802154_hw *hw)
tasklet_kill(&local->tasklet);
flush_workqueue(local->workqueue);
+ /*
+ * Drain mac_wq before unregistering interfaces; some workers access
+ * sub-interface data and acquire rtnl themselves.
+ */
+ drain_workqueue(local->mac_wq);
rtnl_lock();
--
2.43.0
next reply other threads:[~2026-08-28 10:19 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 10:19 Xuanqiang Luo [this message]
2026-08-31 8:10 ` [PATCH net v1] mac802154: drain mac_wq before unregistering interfaces Miquel Raynal
2026-09-01 1:24 ` Xuanqiang Luo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828101905.26865-1-xuanqiang.luo@linux.dev \
--to=xuanqiang.luo@linux.dev \
--cc=alex.aring@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wpan@vger.kernel.org \
--cc=luoxuanqiang@kylinos.cn \
--cc=miquel.raynal@bootlin.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stefan@datenfreihafen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.