From: Jakub Sitnicki <jakub@cloudflare.com>
To: Chengfeng Ye <nicoyip.dev@gmail.com>
Cc: Emil Tsalapatis <emil@etsalapatis.com>,
Eric Dumazet <edumazet@google.com>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
John Fastabend <john.fastabend@gmail.com>,
Jiayuan Chen <jiayuan.chen@linux.dev>,
"David S. Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
netdev@vger.kernel.org, bpf@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH bpf v4] bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
Date: Fri, 24 Jul 2026 12:48:22 +0200 [thread overview]
Message-ID: <87a4rgll3d.fsf@cloudflare.com> (raw)
In-Reply-To: <20260724103856.3399001-1-nicoyip.dev@gmail.com> (Chengfeng Ye's message of "Fri, 24 Jul 2026 18:38:56 +0800")
On Fri, Jul 24, 2026 at 06:38 PM +08, Chengfeng Ye wrote:
> tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
> drops and reacquires the socket lock. Its error path tries to decide
> whether msg_tx names the local temporary message by comparing it with
> the current value of psock->cork.
>
> This comparison is unsafe when two threads send on the same socket:
>
> Thread A Thread B
> msg_tx = psock->cork
> sk_msg_alloc() fails
> sk_stream_wait_memory()
> releases the socket lock acquires the socket lock
> completes the cork
> psock->cork = NULL
> frees the cork
> reacquires the socket lock
> msg_tx != psock->cork
> sk_msg_free(msg_tx)
>
> The stale cork is therefore mistaken for the local temporary message
> and freed again. KASAN reported:
>
> BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50
> Read of size 4 at addr ffff88810c908800 by task poc/90
> Call Trace:
> sk_msg_free+0x49/0x50
> tcp_bpf_sendmsg+0x14f5/0x1cc0
> __sys_sendto+0x32c/0x3a0
> __x64_sys_sendto+0xdb/0x1b0
> Allocated by task 89:
> __kasan_kmalloc+0x8f/0xa0
> tcp_bpf_sendmsg+0x16b3/0x1cc0
> Freed by task 91:
> __kasan_slab_free+0x43/0x70
> kfree+0x131/0x3c0
> tcp_bpf_sendmsg+0xec3/0x1cc0
>
> msg_tx can only name the stack-local tmp or the shared cork. Check for
> tmp directly so a changed psock->cork cannot turn a shared message into
> an apparent local one.
>
> Fixes: 604326b41a6f ("bpf, sockmap: convert to generic sk_msg interface")
> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> ---
Thanks!
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
next prev parent reply other threads:[~2026-07-24 10:48 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-19 16:16 [PATCH] bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() Chengfeng Ye
2026-07-20 16:17 ` sashiko-bot
2026-07-20 20:12 ` Emil Tsalapatis
2026-07-23 15:41 ` Chengfeng Ye
2026-07-23 15:34 ` [PATCH v2] bpf, sockmap: Fix cork ownership " Chengfeng Ye
2026-07-23 15:49 ` sashiko-bot
2026-07-23 16:26 ` [PATCH v3] " Chengfeng Ye
2026-07-23 16:39 ` sashiko-bot
2026-07-23 17:00 ` Jakub Kicinski
2026-07-24 9:40 ` Jakub Sitnicki
2026-07-24 10:02 ` Chengfeng Ye
2026-07-24 10:07 ` Jakub Sitnicki
2026-07-24 10:38 ` [PATCH bpf v4] bpf, sockmap: Fix cork use-after-free " Chengfeng Ye
2026-07-24 10:48 ` Jakub Sitnicki [this message]
2026-07-24 10:56 ` sashiko-bot
2026-07-24 10:43 ` [PATCH v3] bpf, sockmap: Fix cork ownership " Chengfeng Ye
2026-07-23 17:44 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87a4rgll3d.fsf@cloudflare.com \
--to=jakub@cloudflare.com \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=emil@etsalapatis.com \
--cc=horms@kernel.org \
--cc=jiayuan.chen@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=nicoyip.dev@gmail.com \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.