From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B76B4374A12 for ; Mon, 24 Aug 2026 03:34:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787542489; cv=none; b=TPYhNFtTjceJqXI+croAkSmlGg90hsJPpy4sprVzIc/hukky3KSzU/5qBz3DKWFyX1Fs1oCkD1BYV/3LVO6sxtDxghmR2q4SStpjFJnxfmpINTvZCPXfTb0EhGRt/5mh8aqJdZxpkdRjq1Gf5NHdEH0zkVeOE169HmDM18XDMOw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787542489; c=relaxed/simple; bh=sz4I1sq4K0b/4zGjd0FzYdICKmLEOx+P2s0EyxNw1ck=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UsExpWf9OT5TVYPUKtJ31HrdpJX2ThevCo5GmrQNSY7roML6soZUHb8r0xcyXGzr2eXYMqPFKnn8AmlOUGw0Xk/2GdKgTCZJs3cmBID5gfRzSjuDXrdk8TLKZ9D26KGsImMYcXfhf9VfZY6uiXKizBRpL/lkrKXEsWjiyeDvTAg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=UD75Iysx; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="UD75Iysx" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-38e42560ebcso2205304a91.1 for ; Sun, 23 Aug 2026 20:34:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787542487; x=1788147287; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=h3czPEGgc8kYZ51pcfr/0w7zOEtrgQWrgOFC5Loyaz4=; b=UD75Iysx8wdyY58cFjzUVXdFvohgn4QrSvPOepcBrVuUaLz8D+ip2mLntd5qFPE2Fr lEZzPZqcny2Ny6mYcbHK6j8vjnQNplMDE4sW9vUH5s/2xn0RIEI9X/FzQDMApEmfCYow Cs4bo0vlGl1Do3QCubUmrZBaQDo0ojeod82X2JrVhpkI48pZxgMXyH9Hspah+vnHWSO7 r8So9mIeFEscjcV2qFT6lUpsIGrIqy/2cShFPckUz4fpabmhGctpyEFlNeXuy52JgWAE ZoXtRc44mNiGBHPoq5gjWN8nT2tNCA5JhwDV8A+cWsboX59fhoBx8CBYUDFBxbpqWR86 i0qA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787542487; x=1788147287; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=h3czPEGgc8kYZ51pcfr/0w7zOEtrgQWrgOFC5Loyaz4=; b=Vd18fMdV4tv3nSQ35ACM9sf0p+koJG+pssHr4caKQo5WYO3u2/c9iTgLWffV6xjhGW sFhBgLsMK40obOkyddnlC7MVuLHjDa2t5EJUTieAmZ5bTizIQJTtY1K1Ev1ChYTALdj3 hqxjUwkHwCQvZWtG2Ipi7todHBI/MKiV68I60TL2H2h2iq9jPL2CnQr3qpcE8j1EU+uC Mx0itL4T4rOCuHj3XPMsQV8af9C8o+u0rs5sui58iGtw5mAGSLImCg5quxQdia2JOmow 5cMcYpUAn+/A/PqJpH8bbrUpDXevS44KFpxlND3nUgGtxrdSHFvkB3zugf6dIb50no5s 2UOA== X-Forwarded-Encrypted: i=1; AHgh+RrSRc+nGvO/dap1VdbX5R7wJ7V8Sv9dAKouutQKwqhmGic/G5ID60KLn22cRXNhuePN5iMgHY6eZ3xp2M0=@vger.kernel.org X-Gm-Message-State: AFuF++lN43PdKseXtbEg3GbkOKkjL2ndiGhSox6ItBMX8yA1ZOc1dTF0 LEu2z+ILeAwC4TZ9QQtXHJIxYvvabDupS1VC9VTrESlGvyNGKDK9/dyx X-Gm-Gg: AR+sD12lq7+EPRSFtOjIOspe7II63DZqn+DfAhZoEhV2jiMsDB15uCBKnnph7mdiscS Zpd5eKoCsMDumkN1uqMcYG1sTnunP6r4+rLipZ3Z+hssXf7BThBMp37kfuSWZsT83yCuSBvmZ3T OjPrfVp4VLF56fNXtLe2d7q3T0q4WxFINeAfQGLh9EDeFMZW+XAJq9x7clWVDQ+1aMFxegdECmx oZKa2u5uqmwcmkZIPDkwiwge1DYO8Tf3+h7IOB5unWIm5qPMHUsJsIAWVgIAoiUokoTFoGFpjMX Q9xyE+3g1xhdmOEGjm99HgWL2KTqkK5Z+8Achdbdze1XMLSVXaXaCUoksFohMTHwF0d6gFsOqpS iRmDsDj3GZZlzOP7TnFFQYjs4nRoef1YooCtWeHBU/4CCOQ6TcXW5SlAQjFdcwq3gnI3FhFWMUG +/lufgGzzLv7GSo7Pm54z4FwhqGA1yEMK29WiUXwHZ1Us6v/6JdRM1jPen4fv7WcdFTxCMEd0YY Fv4x/Htq0PrgWVhIh2BkQ== X-Received: by 2002:a17:90b:5805:b0:38e:485c:ebd3 with SMTP id 98e67ed59e1d1-395c3a514a5mr42206353a91.15.1787542486850; Sun, 23 Aug 2026 20:34:46 -0700 (PDT) Received: from v4bel.. ([58.123.110.97]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-395c8fd34d9sm4227256a91.1.2026.08.23.20.34.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 23 Aug 2026 20:34:46 -0700 (PDT) From: Hyunwoo Kim To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, ncardwell@google.com, dsahern@kernel.org, idosch@nvidia.com, kuniyu@google.com, horms@kernel.org, willemb@google.com, andrew+netdev@lunn.ch, kees@kernel.org, jiayuan.chen@linux.dev Cc: kerneljasonxing@gmail.com, ij@kernel.org, martin.lau@kernel.org, shakeel.butt@linux.dev, matttbe@kernel.org, martineau@kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, imv4bel@gmail.com, stable@vger.kernel.org Subject: [PATCH net v2 7/8] net: clear sk_tsq_flags in sk_clone() Date: Mon, 24 Aug 2026 12:32:51 +0900 Message-ID: <20260824033331.1084971-8-imv4bel@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260824033331.1084971-1-imv4bel@gmail.com> References: <20260824033331.1084971-1-imv4bel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit A socket returned by accept() can be freed while its fd is still open. A setsockopt() on that fd then hits a use-after-free. TCP_TSQ_DEFERRED owns a socket reference. tcp_tsq_handler() sets the bit and calls sock_hold() when the socket is owned by user, and tcp_release_cb() clears the bit and calls __sock_put(). sock_copy() gives the child the bit but not the reference, so the __sock_put() that runs when accept() locks and unlocks the child has nothing to pair with. The socket is freed by the next put, which in the log below came from a timer. A listener can be holding this bit. An established socket becomes a listener again through connect(AF_UNSPEC) and listen(), and tcp_clear_xmit_timers() only calls hrtimer_try_to_cancel(), so a pacing callback that is already running survives. That callback sets the bit while accept() holds the socket lock, and in the same window the child is created in the TCP_NEW_SYN_RECV branch of tcp_v4_rcv(), which does not take the listener lock. All seven bits in sk_tsq_flags describe work pending on the parent, and four of them own a reference. They are set in four different places, so clear the whole word in sk_clone(). In short: socket(AF_INET) -> setsockopt(SO_MAX_PACING_RATE, 100000) -> setsockopt(TCP_MAXSEG, 1200) -> bind -> connect(peer) send(64KB) // arms the pacing timer, sock_hold() connect(AF_UNSPEC) // stop being connected listen() // become a listener again setsockopt(TCP_DEFER_ACCEPT) // another socket connects, and with TCP_DEFER_ACCEPT there is no // child yet accept() // the child is created when one byte // arrives. while accept() holds the // lock the pacing callback sets the // bit, and the child is cloned by // the receive path, which does not // take the listener lock // a timer on the child does the last put and the socket is freed setsockopt(accepted, TCP_NODELAY) // use-after-free KASAN log: BUG: KASAN: slab-use-after-free in sock_common_setsockopt+0x44/0x80 Read of size 8 at addr ffff88800e2ab668 by task repro/94 ... Call Trace: sock_common_setsockopt+0x44/0x80 do_sock_setsockopt+0x15e/0x2b0 __sys_setsockopt+0x9e/0xe0 __x64_sys_setsockopt+0x64/0x80 ... Allocated by task 95: sk_prot_alloc+0x45/0x170 sk_clone+0x49/0x960 inet_csk_clone_lock+0x29/0x2c0 tcp_create_openreq_child+0x2a/0xf20 tcp_v4_syn_recv_sock+0xd3/0x7e0 tcp_check_req+0x374/0xff0 tcp_v4_rcv+0xc2d/0x2040 ... Freed by task 0: slab_free_after_rcu_debug+0xc5/0x200 rcu_core+0x4de/0xd30 ... Last potentially related work creation: kmem_cache_free+0x11d/0x5f0 __sk_destruct+0x29a/0x3d0 call_timer_fn+0x12f/0x3f0 __run_timers+0x4a4/0x5e0 ... The buggy address belongs to the object at ffff88800e2ab640 which belongs to the cache TCP of size 3200 Fixes: 73a6bab5aa2a ("tcp: switch pacing timer to softirq based hrtimer") Cc: stable@vger.kernel.org Signed-off-by: Hyunwoo Kim --- net/core/sock.c | 1 + 1 file changed, 1 insertion(+) diff --git a/net/core/sock.c b/net/core/sock.c index 098e58b40f304b..06fbb19824e267 100644 --- a/net/core/sock.c +++ b/net/core/sock.c @@ -2533,6 +2533,7 @@ struct sock *sk_clone(const struct sock *sk, const gfp_t priority, newsk->sk_reserved_mem = 0; DEBUG_NET_WARN_ON_ONCE(newsk->sk_drop_counters); sk_drops_reset(newsk); + newsk->sk_tsq_flags = 0; newsk->sk_send_head = NULL; newsk->sk_userlocks = sk->sk_userlocks & ~SOCK_BINDPORT_LOCK; atomic_set(&newsk->sk_zckey, 0); -- 2.43.0