From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B224A372ECC; Tue, 26 May 2026 16:53:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779814384; cv=none; b=k60vp9sI5aib3/9/h4udMHTksI3KFDN0dCt2nwB0gWBYDAs563gB2TaTJj6XUGemNrP3y3LSuQEtzUtcNrXHQTgvPhbgom5U73bai2VqUy0bV8zlYThvhgzuQTr6omTr/nKtqnLD0CKXvyqFRfpGmZwdy5GgU3Sc/ZQUkiO3GIM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779814384; c=relaxed/simple; bh=1LjAskGguz2rfgTsGFjdgHEYYWC/5+g0apQbVjirT74=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=SRXTPHCsRxwMLBBzi6Oin1aqqx4YqgAJCSZYSrUh7Uj8+RHpgtrZacCSc0DXlNL4b+vgp9Wa7tziQs0b8iQWEVziH3x2YbC4eDsJb9KXgdWGA4U2c0hCGW/3aGJKMKuyNyYU4htynE1rHgK4On8qSu/iDNGVGWpdCfL3bfgGzsw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bHUe9s3H; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bHUe9s3H" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 20D511F000E9; Tue, 26 May 2026 16:53:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779814383; bh=6L1yzNzManCBqw0iUGXBvopsXg6RqxnpLx+6+pZbk4k=; h=From:To:Subject:Date; b=bHUe9s3HER94OX/fVTnu0pM2/GinyBNjFZ2sdOi0Yp12+5vXnn8wDfDqtygtCu8Bc Tjzs7tcckiDp3i/HTGeqx5IVl0SAXhsWR0+6IIrwH20WR6tbwO8IxLShSnSXq0xnjV 8qRtF21ivwz+WYfgV5q7Kz0TlA9l/5ZufldJ2B3qu5PJuOLQM92o3sTiKJAsE0L/Rd +532jwyufQxxb2/2txmjhB/sfvWVubBUbrMPZM8G3fo1gqEy6Fetm3cqJvYxPRzfem lAOAzdD3AXt2Ci326I3LqbYIRU3IYBeMMWw5TfSL3umPS1Wf3/gcamhIlfUEnIC5Ww KvvJXw2QHLrYw== From: Lee Jones To: lee@kernel.org, Oliver Hartkopp , Marc Kleine-Budde , linux-can@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 1/1] can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF Date: Tue, 26 May 2026 17:52:56 +0100 Message-ID: <20260526165257.3705239-1-lee@kernel.org> X-Mailer: git-send-email 2.54.0.746.g67dd491aae-goog Precedence: bulk X-Mailing-List: linux-can@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Commit f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly synchronize_rcu()") replaced synchronize_rcu() in bcm_delete_rx_op() with call_rcu() and introduced the RX_NO_AUTOTIMER flag. However, this flag check was omitted for thrtimer in the packet rx fast-path. During BCM RX operation teardown, a concurrent RCU reader (bcm_rx_handler) can race and re-arm thrtimer via bcm_rx_update_and_send() after call_rcu() has been scheduled. Once the RCU grace period elapses, bcm_op is freed. The subsequently firing thrtimer then dereferences the deallocated op, causing a UAF. Adding flag checks to the rx fast-path (bcm_rx_update_and_send) does not fully close the TOCTOU race and introduces latency for every CAN frame. Conversely, calling hrtimer_cancel() directly inside the RCU callback (softirq context) is fatal as hrtimer_cancel() can sleep, triggering a "scheduling while atomic" panic. Resolve this by deferring the timer cancellation and memory free to a dedicated unbound workqueue (bcm_wq). The RCU callback now queues a work item to bcm_wq, which safely cancels both timers and deallocates memory in sleepable process context. A dedicated workqueue is used to prevent system-wide WQ saturation and is cleanly flushed/destroyed on module unload to avoid rmmod page faults. Fixes: f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly synchronize_rcu()") Signed-off-by: Lee Jones --- v1 => v2: New patch using workqueues v2 => v3: Add memory barrier net/can/bcm.c | 29 ++++++++++++++++++++++++++--- 1 file changed, 26 insertions(+), 3 deletions(-) diff --git a/net/can/bcm.c b/net/can/bcm.c index a4bef2c48a55..c49b09f3229f 100644 --- a/net/can/bcm.c +++ b/net/can/bcm.c @@ -58,6 +58,7 @@ #include #include #include +#include #include #include #include @@ -92,6 +93,8 @@ MODULE_ALIAS("can-proto-2"); #define BCM_MIN_NAMELEN CAN_REQUIRED_SIZE(struct sockaddr_can, can_ifindex) +static struct workqueue_struct *bcm_wq; + /* * easy access to the first 64 bit of can(fd)_frame payload. cp->data is * 64 bit aligned so the offset has to be multiples of 8 which is ensured @@ -105,6 +108,7 @@ static inline u64 get_u64(const struct canfd_frame *cp, int offset) struct bcm_op { struct list_head list; struct rcu_head rcu; + struct work_struct work; int ifindex; canid_t can_id; u32 flags; @@ -793,9 +797,12 @@ static struct bcm_op *bcm_find_op(struct list_head *ops, return NULL; } -static void bcm_free_op_rcu(struct rcu_head *rcu_head) +static void bcm_free_op_work(struct work_struct *work) { - struct bcm_op *op = container_of(rcu_head, struct bcm_op, rcu); + struct bcm_op *op = container_of(work, struct bcm_op, work); + + hrtimer_cancel(&op->timer); + hrtimer_cancel(&op->thrtimer); if ((op->frames) && (op->frames != &op->sframe)) kfree(op->frames); @@ -806,6 +813,14 @@ static void bcm_free_op_rcu(struct rcu_head *rcu_head) kfree(op); } +static void bcm_free_op_rcu(struct rcu_head *rcu_head) +{ + struct bcm_op *op = container_of(rcu_head, struct bcm_op, rcu); + + INIT_WORK(&op->work, bcm_free_op_work); + queue_work(bcm_wq, &op->work); +} + static void bcm_remove_op(struct bcm_op *op) { hrtimer_cancel(&op->timer); @@ -1839,11 +1854,15 @@ static int __init bcm_module_init(void) { int err; + bcm_wq = alloc_workqueue("can-bcm-wq", WQ_UNBOUND, 0); + if (!bcm_wq) + return -ENOMEM; + pr_info("can: broadcast manager protocol\n"); err = register_pernet_subsys(&canbcm_pernet_ops); if (err) - return err; + goto register_pernet_failed; err = register_netdevice_notifier(&canbcm_notifier); if (err) @@ -1861,6 +1880,8 @@ static int __init bcm_module_init(void) unregister_netdevice_notifier(&canbcm_notifier); register_notifier_failed: unregister_pernet_subsys(&canbcm_pernet_ops); +register_pernet_failed: + destroy_workqueue(bcm_wq); return err; } @@ -1869,6 +1890,8 @@ static void __exit bcm_module_exit(void) can_proto_unregister(&bcm_can_proto); unregister_netdevice_notifier(&canbcm_notifier); unregister_pernet_subsys(&canbcm_pernet_ops); + rcu_barrier(); + destroy_workqueue(bcm_wq); } module_init(bcm_module_init); -- 2.54.0.746.g67dd491aae-goog