From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f172.google.com (mail-qt1-f172.google.com [209.85.160.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7344E2DF128 for ; Sat, 1 Aug 2026 21:37:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785620260; cv=none; b=o7XN3ehb1u4RMRlaXlepNFTJVUPF5W+zegSaivpkuv54n4SPv/N9SJ0A4cjpeupdbe5fxBgUXIGlERuKiQuAGlTFEHEfzG105ZzwX2pesj7yLz+5yxK+4ipq61CqOcB+uT0bAvaIY6yEhoPnaOM/1am023Dx2lwRiRuU5soXnxo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785620260; c=relaxed/simple; bh=PdcrG7GkMxlOZ4eaudUMpHVF5woUKkG1xAqvC1xgXnA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=L9OlsoQjX+eLe0gzUnH3XJW8BjSX8Y4H/cYRngmtbL51/AxvfId/Vj4I4ZWWkjdazN/tPCEhNDfGMbY2Uwyof674fpKl+csHp2sLeJSyxi21veTzztuVt9Tbehw2g/eO2UqHO+266if32kHpGWP3zGoiCWMyYswMWm56P1xGlFg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BigswsHj; arc=none smtp.client-ip=209.85.160.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BigswsHj" Received: by mail-qt1-f172.google.com with SMTP id d75a77b69052e-51c0c45c580so12786381cf.0 for ; Sat, 01 Aug 2026 14:37:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785620258; x=1786225058; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=G6Et0NhWmlhqF6H6Esm0lrRD3CSb6Cqp9D32iHCNdQ4=; b=BigswsHjpvhURs2nEr5x3PDY7BtwS+iHViS80ZctZEbwla7nmXh7wK0yfcC60pJ8EP Vw8/UQOsncG5We2H4lF0l1mEY2lDV5svCTCj7aJGHYmWdwQ/AFbE0MIBq7HkpWXijzYV Kj5k1ttu4EoAwp1nuRsxYhis+ewC3uaXSwNVAw3b+/VKPSnxEI+4VYtQ+9nRQUIQa26u dIKmV+BilrVMbnHpK+LKqMF1Babz0D8zz+XMdZyh5JJZh/hNcDE4RFZgwIF8IIF1nJN/ +LxbsuiDfPHI5JqwAshctdtkJkMOhCGPu/r9ex+7u8U1UdGWZY5UARFSAGsfWNxoba5c O5IA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785620258; x=1786225058; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=G6Et0NhWmlhqF6H6Esm0lrRD3CSb6Cqp9D32iHCNdQ4=; b=OiFgL7zttGt3OG8nwBtAfHYWJk+guGnDKo/Xy+sYvwWyBQqnE74Crhc9YyOd1axxJZ 2rg4nyZNrAMSEeJFU3vXy5aGwxXEmpuXC8aEKwAHTubJvFtcqETjZJYIyLkaXjxpM5HE 5jGlEnaHy/K+kW/WQw8rGecOheC9hgdcjf/t35EeHALckKSPpKkNwe9RQUvKAigHGwYs /m93pl2CiA1xJF9BnI2yaWYVSkhvFc5LLKphyb/7dVI0jPLzRTU4NQGkkwQGqOar1NXW REKXG4QunWz0DrPzqzotQjYLPVcfRCRcGca9R1yc+yhsliyCNkzX7NrpJSPnw3LROMRe vlKw== X-Forwarded-Encrypted: i=1; AHgh+Rpu4LuD7Kucd4IlZFvT9zeq9GX0QDq5pFpQbU6dDfyC1e1gwWnRCgRYlreXCOVm8UBwGY8RRhrXGsf17QI=@vger.kernel.org X-Gm-Message-State: AOJu0YwoHs4VZheVpWACaSCgeKC5OiXNxOlbcNxmK236KXc7bc3MHFhj TVCpO+qkw3EbDduha5aAshQANaHsy9tLKNfL5TPmk8GoC6O90P9hSnw2 X-Gm-Gg: AR+sD10xkbdXWvSE7adukkf3z/LbvwjETDMJeMsgYfDt1EpJ5IC4VneHGUkqfQ9TNd7 oCX19HP943FQSoo6BVbWF2ykkpqHBDxIUNoFQZO3OSa79rUtI5LSKMgpqvnuggFRT1JgF2IObUs 11MvLWMl/X2UfO98kQmePxBugqWwg+MzyJdDTx/5gLwXrqe/4vWrfNN5Z9Cee+8Hg85jHOHbNh9 +nBoRYaVKsj5YCAZ/S1izuiB0lU0cn9o0DVh80f3sFou2TVfjE5CnuRvgwZDyoIfLMfKAJENs9j N09747Ug8sQ0X0a0cA13LrG9SCpvAj3mBLck/LP7gwry9Rd63bXt9RrFvwu6H57S0QdJavIrTmc 8x4XQ2odIc6zjQPBOaoXCLfra4BvZM4KK7Ezw+ZAWpzZkZNd9Wen5fdkD4R0cm4GHssSQIbQu4X hVV6BD6JS/4kbZSsxuVlhbnQvSYgcnp5w0ZNrtRiNEbFLi+YU3UkNyFB08erxC9F1kC6X3VYm3x oybdJeVgxiMzbzExw== X-Received: by 2002:a05:622a:22a2:b0:519:e020:6087 with SMTP id d75a77b69052e-52b5679fb54mr98575971cf.11.1785620258384; Sat, 01 Aug 2026 14:37:38 -0700 (PDT) Received: from i4-l-hqh5357-03.ad.psu.edu ([130.203.139.71]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-908435b6adesm40376256d6.24.2026.08.01.14.37.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 01 Aug 2026 14:37:38 -0700 (PDT) From: Shuangpeng Bai To: bernard.metzler@linux.dev, jgg@ziepe.ca, leon@kernel.org Cc: linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org, Shuangpeng Bai , stable@vger.kernel.org Subject: [PATCH] RDMA/siw: Fix use-after-free in siw_accept() Date: Sat, 1 Aug 2026 17:36:32 -0400 Message-ID: <20260801213632.1086548-1-shuangpeng.kernel@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit siw_accept() looks up the QP supplied by userspace. If that QP is already in RTS, the function jumps to error cleanup before associating the incoming CEP with it. The cleanup tests whether qp->cep is non-NULL and assumes the current call installed the association. However, qp->cep can point to the CEP of an existing connection. The cleanup then drops a reference from the incoming cep, not qp->cep. Once the incoming endpoint loses its remaining references, this can free it before the subsequent cep->qp store, causing a use-after-free. It also clears the existing QP association. Only release the association reference when qp->cep is the incoming CEP. This preserves an existing association and avoids accessing the freed endpoint. Fixes: 6c52fdc244b5 ("rdma/siw: connection management") Cc: stable@vger.kernel.org Signed-off-by: Shuangpeng Bai --- drivers/infiniband/sw/siw/siw_cm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c index 87c79527ac09..0245b25e7271 100644 --- a/drivers/infiniband/sw/siw/siw_cm.c +++ b/drivers/infiniband/sw/siw/siw_cm.c @@ -1751,7 +1751,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params) cep->state = SIW_EPSTATE_CLOSED; siw_free_cm_id(cep); - if (qp->cep) { + if (qp->cep == cep) { siw_cep_put(cep); qp->cep = NULL; } -- 2.43.0