Netdev List
 help / color / mirror / Atom feed
From: Paolo Abeni <pabeni@redhat.com>
To: Alexandra Winter <wintera@linux.ibm.com>,
	Hidayath Khan <hidayath@linux.ibm.com>,
	davem@davemloft.net, edumazet@google.com, kuba@kernel.org
Cc: horms@kernel.org, linux-s390@vger.kernel.org,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	twinkler@linux.ibm.com, heiko.carstens@de.ibm.com,
	gor@linux.ibm.com, agordeev@linux.ibm.com,
	borntraeger@linux.ibm.com, svens@linux.ibm.com
Subject: Re: [PATCH net] net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
Date: Tue, 21 Jul 2026 18:02:24 +0200	[thread overview]
Message-ID: <593ad84c-279d-4d3e-8137-f48188c45c8e@redhat.com> (raw)
In-Reply-To: <fff72695-88b5-4ba5-b1f4-f70a2b02ed1b@linux.ibm.com>

On 7/21/26 3:54 PM, Alexandra Winter wrote:
> On 09.07.26 21:17, Hidayath Khan wrote:
>> afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.
>> If the allocation fails, nsk is NULL.
>>
>> The connection-refused path is entered when the listen state check
>> fails, the accept backlog is full, or nsk is NULL. The code
>> unconditionally calls iucv_sock_kill(nsk) in that path.
>>
>> iucv_sock_kill() does not accept a NULL socket pointer and immediately
>> dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,
>> calling iucv_sock_kill(nsk) results in a NULL pointer dereference.
>>
>> Only call iucv_sock_kill() when a child socket was successfully
>> allocated.
>>
>> Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport")
>> Cc: stable@vger.kernel.org
>> Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
>> Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
>> ---
>>  net/iucv/af_iucv.c | 3 ++-
>>  1 file changed, 2 insertions(+), 1 deletion(-)
>>
>> diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
>> index fed240b453bd..f5b1ec44b6ae 100644
>> --- a/net/iucv/af_iucv.c
>> +++ b/net/iucv/af_iucv.c
>> @@ -1872,7 +1872,8 @@ static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
>>  		afiucv_swap_src_dest(skb);
>>  		trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
>>  		err = dev_queue_xmit(skb);
>> -		iucv_sock_kill(nsk);
>> +		if (nsk)
>> +			iucv_sock_kill(nsk);
>>  		bh_unlock_sock(sk);
>>  		goto out;
>>  	}
>>
>> base-commit: 262b2eac463d880a664cf92af1107b4f9d84ad37
> 
> 
> Gentle ping to netdev maintainers:
> Did this one get lost in the overflow?
> It is all green in patchwork. Is there something you need us to do?
> Should we re-send it?
> I don't see this as urgent or especially dangerous.
It's still alive in PW. Our backlog is unusually huge due to an
unfortunate sequence of season holidays and conferences, but hopefully
it should get back to normality someday in the future :)

/P


  reply	other threads:[~2026-07-21 16:03 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-09 19:17 [PATCH net] net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() Hidayath Khan
2026-07-10  9:34 ` Jagielski, Jedrzej
2026-07-10 16:20   ` Hidayathulla Khan I
2026-07-12  7:56 ` Hidayathulla Khan I
2026-07-21 13:54 ` Alexandra Winter
2026-07-21 16:02   ` Paolo Abeni [this message]
2026-07-21 21:00 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=593ad84c-279d-4d3e-8137-f48188c45c8e@redhat.com \
    --to=pabeni@redhat.com \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=gor@linux.ibm.com \
    --cc=heiko.carstens@de.ibm.com \
    --cc=hidayath@linux.ibm.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=svens@linux.ibm.com \
    --cc=twinkler@linux.ibm.com \
    --cc=wintera@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox