From: Sven Eckelmann <sven@narfation.org>
To: sashiko-reviews@lists.linux.dev
Cc: marek.lindner@mailbox.org, sw@simonwunderlich.de,
antonio@mandelbit.com, netdev@vger.kernel.org
Subject: Re: [PATCH net-next 06/15] batman-adv: ensure u16 aligned mac address arrays on stack
Date: Tue, 01 Sep 2026 18:59:04 +0200 [thread overview]
Message-ID: <3637364.QJadu78ljV@sven-desktop> (raw)
In-Reply-To: <20260901140000.035F51F000E9@smtp.kernel.org>
[-- Attachment #1: Type: text/plain, Size: 1627 bytes --]
On Tuesday, 1 September 2026 15:59:59 CEST sashiko-bot@kernel.org wrote:
[...]
> If memory allocation fails for bat_priv->bla.backbone_hash, the previously
> allocated claim_hash is destroyed but the pointer is left dangling:
>
> net/batman-adv/bridge_loop_avoidance.c:batadv_bla_init() {
> ...
> bat_priv->bla.backbone_hash = batadv_hash_new(32);
> if (!bat_priv->bla.backbone_hash) {
> batadv_hash_destroy(bat_priv->bla.claim_hash);
> return -ENOMEM;
> }
> ...
> }
>
> This failure propagates up to batadv_mesh_init() and register_netdevice(),
> which rolls back by calling the device's priv_destructor
> (batadv_meshif_free()).
>
> This destructor calls batadv_mesh_free() which unconditionally calls
> batadv_bla_free(). Could batadv_bla_free() then use the dangling non-NULL
> claim_hash pointer:
>
> net/batman-adv/bridge_loop_avoidance.c:batadv_bla_free() {
> ...
> if (bat_priv->bla.claim_hash) {
> batadv_bla_purge_claims(bat_priv, primary_if, 1);
> batadv_hash_destroy(bat_priv->bla.claim_hash);
> bat_priv->bla.claim_hash = NULL;
> }
> ...
> }
>
> leading to a use-after-free in batadv_bla_purge_claims() and a double free
> via batadv_hash_destroy()?
>
> Would it be safer to set bat_priv->bla.claim_hash = NULL immediately after
> destroying it in batadv_bla_init()?
>
>
Completely out-of-scope for this patch. Submitted patch for review to
https://patch.msgid.link/20260901-claim-avoid-err-double-free-v1-1-6d6f081f5151@narfation.org
Regards,
Sven
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
next prev parent reply other threads:[~2026-09-01 16:59 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 13:51 [PATCH net-next 00/15] pull request for net-next: batman-adv 2026-08-31 Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 01/15] batman-adv: dat: fix printing of unknown 4addr subtype Simon Wunderlich
2026-09-01 17:03 ` Sven Eckelmann
2026-09-04 22:51 ` patchwork-bot+netdevbpf
2026-08-31 13:51 ` [PATCH net-next 02/15] batman-adv: drop direction in _batadv_is_ap_isolated kernel-doc Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 03/15] batman-adv: bat_v: fix bonding candidate selection Simon Wunderlich
[not found] ` <20260901135959.23F6C1F000E9@smtp.kernel.org>
2026-09-01 16:58 ` Sven Eckelmann
2026-09-01 17:10 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 04/15] batman-adv: clarify cut-off in batadv_v_neigh_is_sob kernel-doc Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 05/15] batman-adv: use more descriptive var names for is_similar_or_better Simon Wunderlich
2026-09-01 17:20 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 06/15] batman-adv: ensure u16 aligned mac address arrays on stack Simon Wunderlich
[not found] ` <20260901140000.035F51F000E9@smtp.kernel.org>
2026-09-01 16:59 ` Sven Eckelmann [this message]
2026-08-31 13:51 ` [PATCH net-next 07/15] batman-adv: ensure u16 aligned mac address in structs Simon Wunderlich
2026-09-01 17:24 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 08/15] batman-adv: tt: remove only the entry which was looked up from the hash Simon Wunderlich
[not found] ` <20260901140001.59CD41F000E9@smtp.kernel.org>
2026-09-01 16:59 ` Sven Eckelmann
2026-09-01 18:11 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 09/15] batman-adv: tt: extract code handling a roam on add Simon Wunderlich
[not found] ` <20260901140002.533041F000E9@smtp.kernel.org>
2026-09-01 16:58 ` Sven Eckelmann
2026-09-01 18:14 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 10/15] batman-adv: tt: simplify NEW flag transition code Simon Wunderlich
2026-09-01 18:18 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 11/15] batman-adv: tt: drop unnecessary cleanup goto in helpers Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 12/15] batman-adv: tt: use protected flag modifications Simon Wunderlich
[not found] ` <20260901140003.62B041F000E9@smtp.kernel.org>
2026-09-01 16:58 ` Sven Eckelmann
2026-09-01 19:21 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 13/15] batman-adv: tt: transition NEW local entries only under lock Simon Wunderlich
2026-09-01 19:31 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 14/15] batman-adv: tt: don't uncount never committed clients on pending purge Simon Wunderlich
2026-09-01 19:33 ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 15/15] batman-adv: tt: decrement count for committed client on local_remove Simon Wunderlich
2026-09-01 19:36 ` Sven Eckelmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3637364.QJadu78ljV@sven-desktop \
--to=sven@narfation.org \
--cc=antonio@mandelbit.com \
--cc=marek.lindner@mailbox.org \
--cc=netdev@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sw@simonwunderlich.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.