From: Dust Li <dust.li@linux.alibaba.com>
To: Mahanta Jambigi <mjambigi@linux.ibm.com>,
andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
kuba@kernel.org, pabeni@redhat.com, alibuda@linux.alibaba.com,
sidraya@linux.ibm.com, hidayath@linux.ibm.com
Cc: pasic@linux.ibm.com, horms@kernel.org, tonylu@linux.alibaba.com,
guwen@linux.alibaba.com, netdev@vger.kernel.org,
linux-s390@vger.kernel.org
Subject: Re: [PATCH net] net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
Date: Fri, 31 Jul 2026 15:15:48 +0800 [thread overview]
Message-ID: <amxLpKV3OBZ3rxus@linux.alibaba.com> (raw)
In-Reply-To: <20260729130153.970800-1-mjambigi@linux.ibm.com>
On 2026-07-29 15:01:53, Mahanta Jambigi wrote:
>The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in
>smc_llc_event_handler() stores an incoming qentry into the local LLC flow
>without first checking whether a qentry is already pending. If a malicious or
>buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is
>active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the
>pointer without freeing the previous allocation, leaking one kmalloc-96 object
>per spurious message.
>
>The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry
>guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a
>duplicate message when qentry is already occupied falls through to break and is
>freed by the kfree(qentry) at the out: label, rather than silently leaking the
>existing allocation.
>
>The response direction (smc_llc_rx_response()) is unaffected: it already guards
>with flow->qentry at the equivalent site and drops duplicate responses
>correctly.
>
>Fixes: 0fb0b02bd6fd ("net/smc: adapt SMC client code to use the LLC flow")
>Signed-off-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
>Reviewed-by: Hidayath Khan <hidayath@linux.ibm.com>
>Reviewed-by: Sidraya Jayagond <sidraya@linux.ibm.com>
>---
> net/smc/smc_llc.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
>diff --git a/net/smc/smc_llc.c b/net/smc/smc_llc.c
>index 954b2ff1815c..aa6d83af55ed 100644
>--- a/net/smc/smc_llc.c
>+++ b/net/smc/smc_llc.c
>@@ -1927,7 +1927,8 @@ static void smc_llc_event_handler(struct smc_llc_qentry *qentry)
> return;
> case SMC_LLC_CONFIRM_LINK:
> case SMC_LLC_ADD_LINK_CONT:
>- if (lgr->llc_flow_lcl.type != SMC_LLC_FLOW_NONE) {
>+ if (lgr->llc_flow_lcl.type != SMC_LLC_FLOW_NONE &&
>+ !lgr->llc_flow_lcl.qentry) {
I read sashiko's review comments, and I think both of them make sense, but
they were pre-existing issues. So I think we can solve them in the future
patches.
https://sashiko.dev/#/patchset/20260729130153.970800-1-mjambigi@linux.ibm.com
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Best regards,
Dust
prev parent reply other threads:[~2026-07-31 7:21 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 13:01 [PATCH net] net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() Mahanta Jambigi
2026-07-30 13:02 ` sashiko-bot
2026-07-31 7:15 ` Dust Li [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amxLpKV3OBZ3rxus@linux.alibaba.com \
--to=dust.li@linux.alibaba.com \
--cc=alibuda@linux.alibaba.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=guwen@linux.alibaba.com \
--cc=hidayath@linux.ibm.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=mjambigi@linux.ibm.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pasic@linux.ibm.com \
--cc=sidraya@linux.ibm.com \
--cc=tonylu@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.