Netdev List
 help / color / mirror / Atom feed
From: "Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
To: Jon Maloy <jmaloy@redhat.com>,
	Tung Quang Nguyen <tung.quang.nguyen@est.tech>
Cc: netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net,
	linux-kernel@vger.kernel.org,
	"Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>,
	stable@vger.kernel.org
Subject: [PATCH net] tipc: protect received keys from concurrent flush
Date: Wed, 30 Sep 2026 11:57:09 +0000	[thread overview]
Message-ID: <20260930115708.349540-2-Jeremy.Jean@oss.cyber.gouv.fr> (raw)

tipc_crypto_key_synch() can queue the RX worker again while it is still
using rx->skey. If tipc_crypto_key_flush() cancels that queued work, it
frees the key without waiting for the running worker. The worker can
then read freed memory or free the key a second time. Racing key
exchange with key flush triggers KASAN:

  [   12.986077] BUG: KASAN: double-free in tipc_crypto_key_flush+0x401/0x530
  [   12.987937] Free of addr ff11000002268080 by task peer/112
  ...
  [   12.991938]  kfree+0x163/0x430
  ...
  [   12.991983]  tipc_crypto_key_flush+0x401/0x530
  ...
  [   12.992152]  tipc_nl_node_flush_key+0x174/0x210

Mark the key as in use under rx->lock and make flush skip it while the
worker is using it. Clear the flag under the same lock when the worker
frees the key or leaves it for retry. Keep rx->skey set so the receive
path cannot replace it during AEAD setup.

Fixes: 1ef6f7c9390f ("tipc: add automatic session key exchange")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
---
 net/tipc/crypto.c | 16 ++++++++++++++--
 1 file changed, 14 insertions(+), 2 deletions(-)

diff --git a/net/tipc/crypto.c b/net/tipc/crypto.c
index 16f1ed1f6b1b..6eb9de458902 100644
--- a/net/tipc/crypto.c
+++ b/net/tipc/crypto.c
@@ -184,6 +184,7 @@ struct tipc_crypto_stats {
  * @key: the key states
  * @skey_mode: session key's mode
  * @skey: received session key
+ * @skey_in_use: received session key is owned by the RX worker
  * @wq: common workqueue on TX crypto
  * @work: delayed work sched for TX/RX
  * @key_distr: key distributing state
@@ -208,6 +209,7 @@ struct tipc_crypto {
 	u16 key_gen;
 	struct tipc_key key;
 	u8 skey_mode;
+	bool skey_in_use;
 	struct tipc_aead_key *skey;
 	struct workqueue_struct *wq;
 	struct delayed_work work;
@@ -1219,8 +1221,11 @@ void tipc_crypto_key_flush(struct tipc_crypto *c)
 		rx = c;
 		tx = tipc_net(rx->net)->crypto_tx;
 		if (cancel_delayed_work(&rx->work)) {
-			kfree_sensitive(rx->skey);
-			rx->skey = NULL;
+			/* A previous invocation may still be using the key. */
+			if (!rx->skey_in_use) {
+				kfree_sensitive(rx->skey);
+				rx->skey = NULL;
+			}
 			atomic_xchg(&rx->key_distr, 0);
 			tipc_node_put(rx->node);
 		}
@@ -2381,7 +2386,10 @@ static void tipc_crypto_work_rx(struct work_struct *work)
 	}
 
 	/* Case 2: Attach a pending received session key from peer if any */
+	spin_lock_bh(&rx->lock);
 	if (rx->skey) {
+		rx->skey_in_use = true;
+		spin_unlock_bh(&rx->lock);
 		rc = tipc_crypto_key_init(rx, rx->skey, rx->skey_mode, false);
 		if (unlikely(rc < 0))
 			pr_warn("%s: unable to attach received skey, err %d\n",
@@ -2391,14 +2399,18 @@ static void tipc_crypto_work_rx(struct work_struct *work)
 		case -ENOMEM:
 			/* Resched the key attaching */
 			resched = true;
+			spin_lock_bh(&rx->lock);
 			break;
 		default:
 			synchronize_rcu();
+			spin_lock_bh(&rx->lock);
 			kfree_sensitive(rx->skey);
 			rx->skey = NULL;
 			break;
 		}
+		rx->skey_in_use = false;
 	}
+	spin_unlock_bh(&rx->lock);
 
 	if (resched && queue_delayed_work(tx->wq, &rx->work, delay))
 		return;
-- 
2.47.3


             reply	other threads:[~2026-09-30 11:58 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 11:57 Jérémy Jean [this message]
2026-10-02  2:57 ` [PATCH net] tipc: protect received keys from concurrent flush netdev-bot+sashiko
2026-10-02 12:05   ` Tung Quang Nguyen
2026-10-02 12:39     ` Jérémy Jean
2026-10-02 12:09 ` Tung Quang Nguyen
2026-10-02 12:42   ` Jérémy Jean
2026-10-02 12:50     ` Tung Quang Nguyen
2026-10-02 12:58       ` Jérémy Jean

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930115708.349540-2-Jeremy.Jean@oss.cyber.gouv.fr \
    --to=jeremy.jean@oss.cyber.gouv.fr \
    --cc=jmaloy@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=tipc-discussion@lists.sourceforge.net \
    --cc=tung.quang.nguyen@est.tech \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox