From: Hyunwoo Kim <imv4bel@gmail.com>
To: Sabrina Dubroca <sd@queasysnail.net>
Cc: netdev@vger.kernel.org, stable@vger.kernel.org, imv4bel@gmail.com
Subject: Re: [PATCH net v3] strparser: make sure __strp_recv isn't running before tearing down the parser
Date: Mon, 5 Oct 2026 22:56:10 +0900 [thread overview]
Message-ID: <asOseirrkC5YC6qf@v4bel> (raw)
In-Reply-To: <425d9d926709b542ed5331110c19fee4aee1f28d.1791206940.git.sd@queasysnail.net>
On Mon, Oct 05, 2026 at 03:50:02PM +0200, Sabrina Dubroca wrote:
> The comment above strp_done() claims that if strp is stopped,
> strp_recv will no longer be called. That's only true if the caller has
> a mechanism (eg locking) to guarantee that strp_recv() calls that
> started before strp_stop() have completed by the time we call
> strp_done().
>
> This adds a dummy lock_sock/release_sock pair to guarantee that any
> in-flight strp_recv() (which runs under either bh_lock_sock or
> lock_sock, depending if it's called from ->sk_data_ready or strp_work)
> has completed.
>
> Only espintcp can be affected by this race condition, but this patch
> makes sure no future user of strp can have the bug.
>
> This could crash on strp->sk ("general mode" of strp), but this mode
> has been here for 9 years and has never been used. It'll be gone soon,
> no point worrying about it.
>
> Switch the stopped/paused/etc bits to u8's to avoid races between
> strp_stop() and strp_pause/unpause().
>
> A reproducer has been published and turns the possible UAF into an
> exploit [1].
:(
>
> Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
> Link: https://lore.kernel.org/all/aZLn2Faeg1FB7XOf@v4bel/
> Link: https://lore.kernel.org/all/aZgpkyTDU3aXe_V0@v4bel/
> Link: https://github.com/m0x41nos/RustyTux [1]
> Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
> Cc: stable@vger.kernel.org
> Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Hyunwoo Kim <imv4bel@gmail.com>
next prev parent reply other threads:[~2026-10-05 13:56 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 13:50 [PATCH net v3] strparser: make sure __strp_recv isn't running before tearing down the parser Sabrina Dubroca
2026-10-05 13:56 ` Hyunwoo Kim [this message]
2026-10-07 1:30 ` patchwork-bot+netdevbpf
2026-10-07 1:32 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asOseirrkC5YC6qf@v4bel \
--to=imv4bel@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=sd@queasysnail.net \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.