All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: Seungwon Bae <qotmddnjs@ajou.ac.kr>
Cc: dhowells@redhat.com, marc.dionne@auristor.com,
	linux-afs@lists.infradead.org, netdev@vger.kernel.org
Subject: Re: [PATCH net] rxrpc: fix use-after-free in rxrpc_poke_conn()
Date: Sat, 5 Sep 2026 15:55:12 +0100	[thread overview]
Message-ID: <20260905145512.GA40544@horms.kernel.org> (raw)
In-Reply-To: <20260901051045.58252-1-qotmddnjs@ajou.ac.kr>

On Tue, Sep 01, 2026 at 02:10:45PM +0900, Seungwon Bae wrote:
> rxrpc_poke_conn() takes a reference on the connection with no liveness
> check, unlike its sibling rxrpc_queue_conn() which gates on
> atomic_read(&conn->active) >= 0.  The per-connection timer is armed with
> no reference held for it, and rxrpc_put_connection() cancels it with a
> non-synchronous timer_delete() only after the refcount reaches 0.
> refcount_t saturates rather than resurrecting, so the connection can be
> kfree()d while still linked in local->conn_attend_q (nothing in teardown
> unlinks attend_link).  The rxrpc I/O thread then performs a UAF write
> (list_del_init) plus UAF reads and indirect calls through conn->security.
> 
> Reproduced on a KASAN + PREEMPT kernel: 56 "refcount_t: addition on 0"
> saturations at load, escalating to
> 
>   BUG: KASAN: slab-use-after-free in rxrpc_io_thread   Write of size 8
> 
> AF_RXRPC socket creation (rxrpc_create) has no capability check, so this
> is reachable by an unprivileged user.
> 
> Guard rxrpc_poke_conn() with the same liveness/refcount check the sibling
> rxrpc_queue_conn() uses before taking the poke reference, so a connection
> past its last-active point is not poked/requeued after teardown began.
> 
> Verified before/after on KASAN+PREEMPT at equal timer volume: 56
> saturations + 15 KASAN reports unpatched vs 0 and 0 patched.
> 

I think a Fixes tag is needed here, citing the patch where
this problem first manifested.

Perhaps this one?

Fixes: f2cce89a074e ("rxrpc: Implement a mechanism to send an event notification to a connection")

If so, there shouldn't be any further action required to that end.
But if you do re-post for some other reason note that
there should not be a blank line between the Fixes and
Signed-off-by tags (or between any other tags).

> Signed-off-by: Seungwon Bae <qotmddnjs@ajou.ac.kr>

...

  reply	other threads:[~2026-09-05 14:55 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01  5:10 [PATCH net] rxrpc: fix use-after-free in rxrpc_poke_conn() Seungwon Bae
2026-09-05 14:55 ` Simon Horman [this message]
2026-09-07 10:02 ` David Howells

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905145512.GA40544@horms.kernel.org \
    --to=horms@kernel.org \
    --cc=dhowells@redhat.com \
    --cc=linux-afs@lists.infradead.org \
    --cc=marc.dionne@auristor.com \
    --cc=netdev@vger.kernel.org \
    --cc=qotmddnjs@ajou.ac.kr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.