* [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt
@ 2025-05-27 16:35 Charalampos Mitrodimas
2025-05-28 1:30 ` Tung Quang Nguyen
2025-05-29 10:10 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 3+ messages in thread
From: Charalampos Mitrodimas @ 2025-05-27 16:35 UTC (permalink / raw)
To: Jon Maloy, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Wang Liang
Cc: netdev, tipc-discussion, linux-kernel,
syzbot+f0c4a4aba757549ae26c, Charalampos Mitrodimas
syzbot reported a refcount warning [1] caused by calling get_net() on
a network namespace that is being destroyed (refcount=0). This happens
when a TIPC discovery timer fires during network namespace cleanup.
The recently added get_net() call in commit e279024617134 ("net/tipc:
fix slab-use-after-free Read in tipc_aead_encrypt_done") attempts to
hold a reference to the network namespace. However, if the namespace
is already being destroyed, its refcount might be zero, leading to the
use-after-free warning.
Replace get_net() with maybe_get_net(), which safely checks if the
refcount is non-zero before incrementing it. If the namespace is being
destroyed, return -ENODEV early, after releasing the bearer reference.
[1]: https://lore.kernel.org/all/68342b55.a70a0220.253bc2.0091.GAE@google.com/T/#m12019cf9ae77e1954f666914640efa36d52704a2
Reported-by: syzbot+f0c4a4aba757549ae26c@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/68342b55.a70a0220.253bc2.0091.GAE@google.com/T/#m12019cf9ae77e1954f666914640efa36d52704a2
Fixes: e27902461713 ("net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done")
Signed-off-by: Charalampos Mitrodimas <charmitro@posteo.net>
---
Changes in v2:
- Return "-ENODEV" instead of "-ENXIO".
- Link to v1: https://lore.kernel.org/r/20250526-net-tipc-warning-v1-1-472f3aa9dd9f@posteo.net
---
net/tipc/crypto.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/tipc/crypto.c b/net/tipc/crypto.c
index 8584893b478510dc1ddda321ed06054de327609b..79f91b6ca8c8477208f13d41a37af24e7aa94577 100644
--- a/net/tipc/crypto.c
+++ b/net/tipc/crypto.c
@@ -818,7 +818,11 @@ static int tipc_aead_encrypt(struct tipc_aead *aead, struct sk_buff *skb,
}
/* Get net to avoid freed tipc_crypto when delete namespace */
- get_net(aead->crypto->net);
+ if (!maybe_get_net(aead->crypto->net)) {
+ tipc_bearer_put(b);
+ rc = -ENODEV;
+ goto exit;
+ }
/* Now, do encrypt */
rc = crypto_aead_encrypt(req);
---
base-commit: 49fffac983ac52aea0ab94914be3f56bcf92d5dc
change-id: 20250526-net-tipc-warning-bda0aa9c5422
Best regards,
--
Charalampos Mitrodimas <charmitro@posteo.net>
^ permalink raw reply related [flat|nested] 3+ messages in thread
* RE: [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt
2025-05-27 16:35 [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt Charalampos Mitrodimas
@ 2025-05-28 1:30 ` Tung Quang Nguyen
2025-05-29 10:10 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: Tung Quang Nguyen @ 2025-05-28 1:30 UTC (permalink / raw)
To: Charalampos Mitrodimas, Jon Maloy, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Simon Horman, Wang Liang
Cc: netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net,
linux-kernel@vger.kernel.org,
syzbot+f0c4a4aba757549ae26c@syzkaller.appspotmail.com
>Subject: [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt
>
>syzbot reported a refcount warning [1] caused by calling get_net() on a
>network namespace that is being destroyed (refcount=0). This happens when a
>TIPC discovery timer fires during network namespace cleanup.
>
>The recently added get_net() call in commit e279024617134 ("net/tipc:
>fix slab-use-after-free Read in tipc_aead_encrypt_done") attempts to hold a
>reference to the network namespace. However, if the namespace is already
>being destroyed, its refcount might be zero, leading to the use-after-free
>warning.
>
>Replace get_net() with maybe_get_net(), which safely checks if the refcount is
>non-zero before incrementing it. If the namespace is being destroyed, return -
>ENODEV early, after releasing the bearer reference.
>
>[1]:
>https://lore.kernel.org/all/68342b55.a70a0220.253bc2.0091.GAE@google.com
>/T/#m12019cf9ae77e1954f666914640efa36d52704a2
>
>Reported-by: syzbot+f0c4a4aba757549ae26c@syzkaller.appspotmail.com
>Closes:
>https://lore.kernel.org/all/68342b55.a70a0220.253bc2.0091.GAE@google.com
>/T/#m12019cf9ae77e1954f666914640efa36d52704a2
>Fixes: e27902461713 ("net/tipc: fix slab-use-after-free Read in
>tipc_aead_encrypt_done")
>Signed-off-by: Charalampos Mitrodimas <charmitro@posteo.net>
>---
>Changes in v2:
>- Return "-ENODEV" instead of "-ENXIO".
>- Link to v1: https://lore.kernel.org/r/20250526-net-tipc-warning-v1-1-
>472f3aa9dd9f@posteo.net
>---
> net/tipc/crypto.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
>diff --git a/net/tipc/crypto.c b/net/tipc/crypto.c index
>8584893b478510dc1ddda321ed06054de327609b..79f91b6ca8c8477208f13d41
>a37af24e7aa94577 100644
>--- a/net/tipc/crypto.c
>+++ b/net/tipc/crypto.c
>@@ -818,7 +818,11 @@ static int tipc_aead_encrypt(struct tipc_aead *aead,
>struct sk_buff *skb,
> }
>
> /* Get net to avoid freed tipc_crypto when delete namespace */
>- get_net(aead->crypto->net);
>+ if (!maybe_get_net(aead->crypto->net)) {
>+ tipc_bearer_put(b);
>+ rc = -ENODEV;
>+ goto exit;
>+ }
>
> /* Now, do encrypt */
> rc = crypto_aead_encrypt(req);
>
>---
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt
2025-05-27 16:35 [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt Charalampos Mitrodimas
2025-05-28 1:30 ` Tung Quang Nguyen
@ 2025-05-29 10:10 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2025-05-29 10:10 UTC (permalink / raw)
To: Charalampos Mitrodimas
Cc: jmaloy, davem, edumazet, kuba, pabeni, horms, wangliang74, netdev,
tipc-discussion, linux-kernel, syzbot+f0c4a4aba757549ae26c
Hello:
This patch was applied to netdev/net.git (main)
by Paolo Abeni <pabeni@redhat.com>:
On Tue, 27 May 2025 16:35:44 +0000 you wrote:
> syzbot reported a refcount warning [1] caused by calling get_net() on
> a network namespace that is being destroyed (refcount=0). This happens
> when a TIPC discovery timer fires during network namespace cleanup.
>
> The recently added get_net() call in commit e279024617134 ("net/tipc:
> fix slab-use-after-free Read in tipc_aead_encrypt_done") attempts to
> hold a reference to the network namespace. However, if the namespace
> is already being destroyed, its refcount might be zero, leading to the
> use-after-free warning.
>
> [...]
Here is the summary with links:
- [net,v2] net: tipc: fix refcount warning in tipc_aead_encrypt
https://git.kernel.org/netdev/net/c/f29ccaa07cf3
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-05-29 10:09 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-05-27 16:35 [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt Charalampos Mitrodimas
2025-05-28 1:30 ` Tung Quang Nguyen
2025-05-29 10:10 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox