From: "Emil Tsalapatis" <emil@etsalapatis.com>
To: "Chengfeng Ye" <nicoyip.dev@gmail.com>,
"Eric Dumazet" <edumazet@google.com>,
"Neal Cardwell" <ncardwell@google.com>,
"Kuniyuki Iwashima" <kuniyu@google.com>,
"John Fastabend" <john.fastabend@gmail.com>,
"Jakub Sitnicki" <jakub@cloudflare.com>,
"Jiayuan Chen" <jiayuan.chen@linux.dev>,
"David S. Miller" <davem@davemloft.net>,
"Jakub Kicinski" <kuba@kernel.org>,
"Paolo Abeni" <pabeni@redhat.com>,
"Simon Horman" <horms@kernel.org>,
"Daniel Borkmann" <daniel@iogearbox.net>,
"Alexei Starovoitov" <ast@kernel.org>,
"open list:BPF [L7 FRAMEWORK] (sockmap)" <bpf@vger.kernel.org>
Cc: <netdev@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<stable@vger.kernel.org>
Subject: Re: [PATCH] bpf, sockmap: Fix sk_redir use-after-free in send verdict
Date: Wed, 29 Jul 2026 01:45:44 -0400 [thread overview]
Message-ID: <DKATFHMTL31E.272MMJP3JGDGG@etsalapatis.com> (raw)
In-Reply-To: <20260719152207.2892156-1-nicoyip.dev@gmail.com>
On Sun Jul 19, 2026 at 11:22 AM EDT, Chengfeng Ye wrote:
> sk_psock_msg_verdict() takes a socket reference for psock->sk_redir.
> tcp_bpf_send_verdict() copies that pointer while holding the source socket
> lock, but does not take a reference for the local copy before dropping the
> lock around tcp_bpf_sendmsg_redir().
>
> When apply_bytes keeps the cached verdict active, another sendmsg() on the
> same source socket can consume the remaining bytes and release the cached
> reference while the first thread still holds only the raw local pointer:
>
> CPU 0 CPU 1
> sk_redir = psock->sk_redir
> apply_bytes remains nonzero
> release_sock(sk)
> lock_sock(sk)
> apply_bytes reaches zero
> psock->sk_redir = NULL
> release_sock(sk)
> tcp_bpf_sendmsg_redir(sk_redir)
> sock_put(sk_redir)
> tcp_bpf_sendmsg_redir(sk_redir)
>
> The final sock_put() can free sk_redir before CPU 0 dereferences it.
>
> KASAN reported:
>
> BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020
> Read of size 8 at addr ffff888108537090 by task poc/87
> Call Trace:
> tcp_bpf_sendmsg_redir+0xf39/0x1020
> tcp_bpf_sendmsg+0x977/0x1a50
> __sys_sendto+0x32c/0x3a0
> __x64_sys_sendto+0xdb/0x1b0
> Allocated by task 85:
> sk_prot_alloc+0x56/0x210
> sk_clone+0x6f/0x14b0
> inet_csk_clone_lock+0x24/0x740
> tcp_create_openreq_child+0x25/0x2710
> tcp_v4_syn_recv_sock+0x10a/0xe00
> Freed by task 0:
> __kasan_slab_free+0x43/0x70
> slab_free_after_rcu_debug+0xa6/0x1e0
> rcu_core+0x50a/0x1850
> Last potentially related work creation:
> __sk_destruct+0x3da/0x540
> sk_psock_destroy+0x81e/0xab0
> process_one_work+0x63a/0x1070
>
> Take a temporary socket reference while the source socket lock still
> protects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir()
> returns. This keeps each unlocked use independent of cached-verdict
> ownership.
>
> Fixes: 604326b41a6f ("bpf, sockmap: convert to generic sk_msg interface")
> Cc: stable@vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
> ---
> net/ipv4/tcp_bpf.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/net/ipv4/tcp_bpf.c b/net/ipv4/tcp_bpf.c
> index 8e905b50dead..69cc8bc33bcd 100644
> --- a/net/ipv4/tcp_bpf.c
> +++ b/net/ipv4/tcp_bpf.c
> @@ -469,6 +469,7 @@ static int tcp_bpf_send_verdict(struct sock *sk, struct sk_psock *psock,
> case __SK_REDIRECT:
> redir_ingress = psock->redir_ingress;
> sk_redir = psock->sk_redir;
> + sock_hold(sk_redir);
> sk_msg_apply_bytes(psock, tosend);
> if (!psock->apply_bytes) {
> /* Clean up before releasing the sock lock. */
> @@ -489,6 +490,7 @@ static int tcp_bpf_send_verdict(struct sock *sk, struct sk_psock *psock,
>
> if (eval == __SK_REDIRECT)
> sock_put(sk_redir);
> + sock_put(sk_redir);
>
> lock_sock(sk);
> sk_mem_uncharge(sk, sent);
prev parent reply other threads:[~2026-07-29 5:45 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-19 15:22 [PATCH] bpf, sockmap: Fix sk_redir use-after-free in send verdict Chengfeng Ye
2026-07-24 23:06 ` John Fastabend
2026-07-29 5:45 ` Emil Tsalapatis [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DKATFHMTL31E.272MMJP3JGDGG@etsalapatis.com \
--to=emil@etsalapatis.com \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jakub@cloudflare.com \
--cc=jiayuan.chen@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=nicoyip.dev@gmail.com \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.