From: Simon Horman <horms@kernel.org>
To: Wentao Liang <vulab@iscas.ac.cn>
Cc: andrew+netdev@lunn.ch, ayush.sawal@chelsio.com,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
pabeni@redhat.com, rohitm@chelsio.com, stable@vger.kernel.org,
Sabrina Dubroca <sd@queasysnail.net>
Subject: Re: [PATCH] chtls: Fix skb reference leak in chtls_send_reset()
Date: Sat, 19 Sep 2026 09:04:28 +0100 [thread overview]
Message-ID: <20260919080428.GX51261@horms.kernel.org> (raw)
In-Reply-To: <20260917105846.2147976-1-vulab@iscas.ac.cn>
+ Sabrina
On Thu, Sep 17, 2026 at 10:58:46AM +0000, Wentao Liang wrote:
> chtls_send_reset() is given a skb holding one reference, to be sent as
> CPL_ABORT_REQ. It consumes that reference on every path except the
> TCP_SYN_RECV one: there it sends a TCB field reply built from a freshly
> allocated skb and never releases the passed-in one.
>
> This leaks the reference taken by reset_listen_child(), which resets
> half-open children in TCP_SYN_RECV found on the SYN queue.
>
> Release the skb on the TCP_SYN_RECV path as well.
>
> Fixes: 8ad2a970d201 ("cxgb4/chtls: Fix tid stuck due to wrong update of qid")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
> drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c b/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> index 0e3e5cf52c2c..a363f20452fa 100644
> --- a/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> +++ b/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> @@ -265,12 +265,14 @@ static void chtls_send_reset(struct sock *sk, int mode, struct sk_buff *skb)
> chtls_purge_write_queue(sk);
>
> csk_set_flag(csk, CSK_ABORT_SHUTDOWN);
> - if (sk->sk_state != TCP_SYN_RECV)
> + if (sk->sk_state != TCP_SYN_RECV) {
> chtls_send_abort(sk, mode, skb);
> - else
> + } else {
> chtls_set_tcb_field_rpl_skb(sk, TCB_T_FLAGS_W,
> TCB_T_FLAGS_V(TCB_T_FLAGS_M), 0,
> TCB_FIELD_COOKIE_TFLAG, 1);
> + kfree_skb(skb);
> + }
>
> return;
> out:
This code change looks reasonable to me.
But the driver was removed in v7.2 by
cdae65fc43f2 ("tls: remove tls_toe and the related driver")
And, as a result it didn't run through our CI.
So while I think it could go to stable
It probably needs more eyes on it.
As an aside, I notice that this driver still appears
in MAINTAINERS in net-next. I will send a patch to remove it.
next prev parent reply other threads:[~2026-09-19 8:04 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 10:58 [PATCH] chtls: Fix skb reference leak in chtls_send_reset() Wentao Liang
2026-09-19 8:04 ` Simon Horman [this message]
2026-09-20 16:25 ` Sabrina Dubroca
2026-09-21 12:13 ` Simon Horman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260919080428.GX51261@horms.kernel.org \
--to=horms@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=ayush.sawal@chelsio.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rohitm@chelsio.com \
--cc=sd@queasysnail.net \
--cc=stable@vger.kernel.org \
--cc=vulab@iscas.ac.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.