Netdev List
 help / color / mirror / Atom feed
* [PATCH net 0/2] vti: fix tunnel device use-after-free across async crypto resumption
@ 2026-09-30  9:08 Qihang
  2026-09-30  9:08 ` [PATCH net 1/2] " Qihang
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Qihang @ 2026-09-30  9:08 UTC (permalink / raw)
  To: netdev; +Cc: steffen.klassert, herbert

vti_input() and vti6_input_proto() cache the tunnel pointer in the skb
control buffer without taking a reference.  With async crypto the
receive callback runs from the crypto completion, so a concurrent
RTM_DELLINK can free the tunnel device before the callback uses the
cached pointer.  The existing rcu_read_lock() around the callback does
not protect it.

Patch 1 fixes the IPv4 side and carries the full description; patch 2
applies the same fix to the IPv6 side.

Qihang (2):
  vti: fix tunnel device use-after-free across async crypto resumption
  vti6: fix tunnel device use-after-free across async crypto resumption

 net/ipv4/ip_vti.c  | 7 +++++++
 net/ipv6/ip6_vti.c | 8 ++++++++
 2 files changed, 15 insertions(+)

-- 
2.54.0 (Apple Git-157)


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-08  1:49 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30  9:08 [PATCH net 0/2] vti: fix tunnel device use-after-free across async crypto resumption Qihang
2026-09-30  9:08 ` [PATCH net 1/2] " Qihang
2026-10-04 10:08   ` netdev-bot+sashiko
2026-10-08  1:49     ` Qihang
2026-09-30  9:08 ` [PATCH net 2/2] vti6: " Qihang
2026-10-04 10:08   ` netdev-bot+sashiko
2026-09-30  9:13 ` [PATCH net 0/2] vti: " netdev-bot+sinfo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox