From: Dust Li <dust.li@linux.alibaba.com>
To: Denis Arefev <arefev@swemel.ru>,
stable@vger.kernel.org,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Karsten Graul <kgraul@linux.ibm.com>,
"David S. Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Ursula Braun <ubraun@linux.ibm.com>,
linux-s390@vger.kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org,
"D . Wythe" <alibuda@linux.alibaba.com>,
Larysa Zaremba <larysa.zaremba@intel.com>,
Wenjia Zhang <wenjia@linux.ibm.com>
Subject: Re: [PATCH 5.10] net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()
Date: Mon, 7 Sep 2026 09:47:56 +0800 [thread overview]
Message-ID: <ap4XzBSJrJMoPJiZ@linux.alibaba.com> (raw)
In-Reply-To: <20260901090545.10419-1-arefev@swemel.ru>
On 2026-09-01 12:05:43, Denis Arefev wrote:
>From: "D. Wythe" <alibuda@linux.alibaba.com>
>
>commit e40b801b3603a8f90b46acbacdea3505c27f01c0 upstream.
>
>There is a certain chance to trigger the following panic:
>
>PID: 5900 TASK: ffff88c1c8af4100 CPU: 1 COMMAND: "kworker/1:48"
> #0 [ffff9456c1cc79a0] machine_kexec at ffffffff870665b7
> #1 [ffff9456c1cc79f0] __crash_kexec at ffffffff871b4c7a
> #2 [ffff9456c1cc7ab0] crash_kexec at ffffffff871b5b60
> #3 [ffff9456c1cc7ac0] oops_end at ffffffff87026ce7
> #4 [ffff9456c1cc7ae0] page_fault_oops at ffffffff87075715
> #5 [ffff9456c1cc7b58] exc_page_fault at ffffffff87ad0654
> #6 [ffff9456c1cc7b80] asm_exc_page_fault at ffffffff87c00b62
> [exception RIP: ib_alloc_mr+19]
> RIP: ffffffffc0c9cce3 RSP: ffff9456c1cc7c38 RFLAGS: 00010202
> RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000004
> RDX: 0000000000000010 RSI: 0000000000000000 RDI: 0000000000000000
> RBP: ffff88c1ea281d00 R8: 000000020a34ffff R9: ffff88c1350bbb20
> R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000000
> R13: 0000000000000010 R14: ffff88c1ab040a50 R15: ffff88c1ea281d00
> ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
> #7 [ffff9456c1cc7c60] smc_ib_get_memory_region at ffffffffc0aff6df [smc]
> #8 [ffff9456c1cc7c88] smcr_buf_map_link at ffffffffc0b0278c [smc]
> #9 [ffff9456c1cc7ce0] __smc_buf_create at ffffffffc0b03586 [smc]
>
>The reason here is that when the server tries to create a second link,
>smc_llc_srv_add_link() has no protection and may add a new link to
>link group. This breaks the security environment protected by
>llc_conf_mutex.
>
>Fixes: 2d2209f20189 ("net/smc: first part of add link processing as SMC server")
>Signed-off-by: D. Wythe <alibuda@linux.alibaba.com>
>Reviewed-by: Larysa Zaremba <larysa.zaremba@intel.com>
>Reviewed-by: Wenjia Zhang <wenjia@linux.ibm.com>
>Signed-off-by: David S. Miller <davem@davemloft.net>
>[Denis Arefev: adapted for 5.10: smc_llc_srv_add_link() has no
>req_qentry argument here, as SMC-Rv2 REQ_ADD_LINK support is
>not present in 5.10]
>Signed-off-by: Denis Arefev <arefev@swemel.ru>
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Best regards,
Dust
prev parent reply other threads:[~2026-09-07 1:48 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 9:05 [PATCH 5.10] net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link() Denis Arefev
2026-09-02 9:06 ` sashiko-bot
2026-09-07 1:47 ` Dust Li [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ap4XzBSJrJMoPJiZ@linux.alibaba.com \
--to=dust.li@linux.alibaba.com \
--cc=alibuda@linux.alibaba.com \
--cc=arefev@swemel.ru \
--cc=davem@davemloft.net \
--cc=gregkh@linuxfoundation.org \
--cc=kgraul@linux.ibm.com \
--cc=kuba@kernel.org \
--cc=larysa.zaremba@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=ubraun@linux.ibm.com \
--cc=wenjia@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.