From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk2-f12.google.com (mail-qk2-f12.google.com [74.125.230.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21D2E4D4868 for ; Tue, 22 Sep 2026 11:50:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.204 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790077861; cv=none; b=l5mpufyGcb2cC+LCr2lJalvcYk3+19cUzMkdnp8wOewQbCSRpTEtLP3UOOyDLvb0Uk9eTfV7Q6zyT9ng3PcotHmV+81N641NkdKZyNOYJRHKwabBxESVquilyzVKVNZkuq77KWb0frhO8M/lOHaDCLMa/ypC1IuUTxd4ectrDFs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790077861; c=relaxed/simple; bh=9Z0/S6ZmABrK+l27B5I2Z8yd1uEctVo+Rmj2z6kxKM4=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=Y1kmjm1E3TzeC1kz9Vrk2LFYHh5QJ5tfM/7SozWqIgEDy7YChm5ThHG+H2jhai6mDU3e8TtuDMpBYrZvNK2rKxKjKowmu6ytkKeetiTr2rgjLMzZYSOv7aEci1Bbw8dWwxu4H7ohxySAAw0f3CUaT7FZ7YobpDGHySOjeaqdCus= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com; spf=none smtp.mailfrom=mojatatu.com; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b=fAZI3SPP; arc=none smtp.client-ip=74.125.230.204 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b="fAZI3SPP" Received: by mail-qk2-f12.google.com with SMTP id d75a77b69052e-5311edbc154so33106181cf.3 for ; Tue, 22 Sep 2026 04:50:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mojatatu.com; s=google; t=1790077859; x=1790682659; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=0saLHrvWxSfUHEQ01OMjuyvbZ8NuQR40GLYKRy9/kyQ=; b=fAZI3SPPERHKxgQmI/DGUMQH1VuMotPv+gSaFIhp5ZVzHOKJC1pQI4ws5VLRZEbNYz Q2UZrnhQFiRCmbx9FFMEkswIkggUl0M4SyEjB8paYTGQc2BRvXVB6GaFOZaecf/K6MiP MsihZJszrKZkDTh7QL9KcdE3Acl5xQgiei/aA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790077859; x=1790682659; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0saLHrvWxSfUHEQ01OMjuyvbZ8NuQR40GLYKRy9/kyQ=; b=p+KF+OachiBZM4SJoL9ZdypGHXgVyBFUlEc+bMDFxkf+w97/IeiTtxNr5OtUYZ3xuo ulGlORgO3HbHgIY6uNDuY1UL4uC3jbvrzDGe7W4en07ovftni2E40CyCwK8QMmRqbaok Lk3wX8ngRNtWXIMqP97ESEW+H0vc07Qy/pIZ878lfiw0E8SgA/cJeVt1mNUW5BK+fkub kApLdDxIYWCurnrYKHJM/mbPFAFnjvSSJXOQFeOlDe0bKPz9qBdllBHmTOcEzi+YbQO8 ZuYvhMkO76yEukvDwKYQ8OdK816ju+IjJ5y4t+9TeV0KF8HPg/PoUuK//s3RA/odRW27 ByFg== X-Gm-Message-State: AFuF++nAVxoTWfWhGBv83+7tA4mVO+wb7II5pofXqCXlS5S1ugxZ8SDx NwYXe1UdktZsHTg+zCTPCd6j9c17z012xjJQUkq5N3HCo7lqTodW/aHGUC/wZxX+W0eFrRhkRlU wYKQVrg== X-Gm-Gg: AYBFou3MLmlfDnSkKotMdyJU/76VJ11cyh9M4GtkBY8Sj8LEWaW69RZ2Pj2AtVYa2uM KfpxjjpkpK/voWUuCXYch6cC/wWov+SwtcsWWntP3ljlB7Ss8FDAODA4ZaQBow7jbwhMkQzVomk QCL7PAX927Y6xh8mQk5HMu7gzipIdkyM2wDtz5JIu8tWEl0hiHmvzGea9wmQf/tH+WZ0jm4G4eb PMRpKd8oy8NnNk6r5sz+qsoNJx+kY47aJTQsS9jcNh2lAFQWHVBXP+dtF5ZszXn2RWK3nttvkA1 KJ+2NVPpS75jL7fNiokiE4UC6G86yp/0u5oIlmiMTUBK91+8MJaV/R8ew44xXKZ03t++WrZ8V6e jEDdd+Q0cQyjLhub4dOP6DRCaRbrlsNHrPKegc6I2ip/YCnQtv2DZ5CdOgUVdjcFHzTe0NYGoBI tZkBnYHWKfZON1Ocwpd3ex0+NmOBBUF0ehJlcA/xy0YUZgenQhbhpasz04S1cETCvQilFLasbA2 hM/DKHveKHrJpF+Kd+VMnlurOnRashdjL9ArehonWpGVFdqUv2BjsOduuCUyspTtz0EqVoibzcC pMLrRVM/8r8HBYe3oQ1laDM= X-Received: by 2002:a05:622a:259b:b0:530:f9e4:a0eb with SMTP id d75a77b69052e-532d8d21d97mr50658031cf.18.1790077858801; Tue, 22 Sep 2026 04:50:58 -0700 (PDT) Received: from majuu.waya (pool-174-112-106-84.cpe.net.cable.rogers.com. [174.112.106.84]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-532e1903c5fsm10927391cf.16.2026.09.22.04.50.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 04:50:57 -0700 (PDT) From: Jamal Hadi Salim To: netdev@vger.kernel.org Cc: Jamal Hadi Salim , stable@vger.kernel.org, Jiri Pirko , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Vlad Buslov , Marcelo Ricardo Leitner , hybris , sashiko-bot@kernel.org Subject: [PATCH net 1/2] net/sched: act_api: reject duplicate actions in a batch Date: Tue, 22 Sep 2026 07:50:54 -0400 Message-Id: X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit tca_action_gd() builds actions[] with one tcf_action_get_1() per nested TCA_ACT_TAB entry. Each successful lookup takes its own reference to the resolved action, so repeated TCA_ACT_INDEX entries in one request yield the same pointer in multiple slots. For RTM_DELACTION, tcf_action_delete() then consumes two references per slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A duplicate therefore drives the refcount to zero mid-walk -- the delete frees the action and removes its IDR slot -- and the next slot calls tcf_action_put() on the freed action: refcount_t: underflow; use-after-free. WARNING: lib/refcount.c:87 at refcount_dec_not_one refcount_dec_and_mutex_lock __tcf_action_put tca_action_gd Three duplicate entries are enough. Reject a repeated action while a delete batch is built, dropping the reference the extra lookup took, and return -EINVAL. RTM_GETACTION balances its own references and keeps accepting duplicate entries. Conditions to recreate the bug: tc actions add action gact index 100 tc actions delete action gact index 100 action gact index 100 \ action gact index 100 Fixes: 16af6067392c ("net: sched: implement reference counted action release") Reported-by: Sashiko (gemini) Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com Tested-by: hybris Signed-off-by: Jamal Hadi Salim --- net/sched/act_api.c | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/net/sched/act_api.c b/net/sched/act_api.c index e45a63be397c..a9323c42a69a 100644 --- a/net/sched/act_api.c +++ b/net/sched/act_api.c @@ -2026,7 +2026,7 @@ static int tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, u32 portid, int event, struct netlink_ext_ack *extack) { - int i, ret; + int i, j, ret; struct nlattr *tb[TCA_ACT_MAX_PRIO + 1]; struct tc_action *act; size_t attr_size = 0; @@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, ret = PTR_ERR(act); goto err; } + + /* A delete consumes two references per slot (tcf_action_put() + * and tcf_idr_delete_index()) but each entry takes one, so a + * repeated action would hit zero mid-walk. GET balances its + * own references and keeps accepting duplicates. + */ + if (event == RTM_DELACTION) { + for (j = 0; j < i - 1; j++) { + if (actions[j] != act) + continue; + + tcf_action_put(act); + NL_SET_ERR_MSG(extack, + "Duplicate TC action in a delete batch"); + ret = -EINVAL; + goto err; + } + } + attr_size += tcf_action_fill_size(act); actions[i - 1] = act; } -- 2.43.0 From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk2-f12.google.com (mail-qk2-f12.google.com [74.125.230.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D52073ABD99 for ; Fri, 25 Sep 2026 08:22:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.204 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790324575; cv=none; b=uch2BEQ+IPT+OhDycPOocI3JYUERqSSmpqO1ICjx2erQcL7wtcRoej1Wk0YoQ+yVDGanz/UUyAjwGYW6UDdTAbRjnh6Rsr88pFXPFs26JKZz1QxXAWRVy/xujkpDLiICCsVAolMz6djgM5Y4yoLTgcUl4Tv7jWFrwbGG3/gaYjc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790324575; c=relaxed/simple; bh=9Z0/S6ZmABrK+l27B5I2Z8yd1uEctVo+Rmj2z6kxKM4=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=eeqnB0NOua7/1W1Pcw/JducJCNd5Y9vZ50JOStJ781MUWmNNWR+Vd6v0o3U4y01wtVuZ1vur6GPTR8eZOQm8d3TlvE3lrlS2+UaelOoquMF3k2zLkcG2olVRTx7HckyBYKzkbrQH2Ul+jNN+G2zconrX09S41Q2ZwnIEMi+pFyM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com; spf=none smtp.mailfrom=mojatatu.com; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b=jYrdhlvU; arc=none smtp.client-ip=74.125.230.204 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b="jYrdhlvU" Received: by mail-qk2-f12.google.com with SMTP id d75a77b69052e-5309a20a55bso7314461cf.1 for ; Fri, 25 Sep 2026 01:22:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mojatatu.com; s=google; t=1790324573; x=1790929373; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=0saLHrvWxSfUHEQ01OMjuyvbZ8NuQR40GLYKRy9/kyQ=; b=jYrdhlvUpgqju2tKjGY5vgmermh2KaVaI8CwRK0bAaMOyb7mcDDPeJOe3/Srlvp0s8 NegrPSYVoG7xmqKUMbz+xKU854XQEvCFUxCeYBmL0MeQNPFCO9t1WRFQdLp+xeziBzl9 hk0nvXdZwr7sSZZYdXcbfsZHCbN7DJMwTxGHI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790324573; x=1790929373; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0saLHrvWxSfUHEQ01OMjuyvbZ8NuQR40GLYKRy9/kyQ=; b=mjsHPNOzcxNcfH0No1zo0aiVdq3LDWFe1fGBw+puRPJqESvJ6fezPiSEMfGsGeWtAh BcpYdV8rQpzbqKQKtwwPR/IZ9tiNVitaOleVE3N1A5jjIPCpr6h9iqf3OMmypV2te0wx qwRrGb7i7kZ/+l4dm0ljJhsBnh2yvAtOqLcALluGtZtyj/YgYC1pC0xGvqOHOLbp3qMT fq/Y6ZxhOs0bfc2++3HCDajZTzMAJkjEoAVmw2XL+qsHQjTsAhN3Gn59GC1aqR8NCkWk NF26np88SPefYc59+MpEDc6OMXY0Jr/CaI1J/xypzeG/DfrmrqpSh6rOyAi1LZrLtAsl PC+w== X-Gm-Message-State: AFuF++lD7S1WO5LA6HumWweFUdHagLJMhlLVUYazk8lL0dYPcIiaW5YV jzmr26YNpp3T3VWhvHHUfYmCIXdiMnuZeCSSccXx1uPmokRey13g7YhYYkKEY7+MVQb84Mz53z5 w/DHPVQ== X-Gm-Gg: AYBFou3pX58wqgnsBfLQIBIkPAnwhLkeCSDPhQh0ZXzwvzrnQ94vIOD1+mc6SFRn2OO UeYSXwUrho1nnQ3selPxNKHqP7H8C8CeqmHSmHg0rt5ilzQZu8QqVPzXeXNR4zSvbJd4IbwTU0g ZkrNY1tIgYDYZdOgU4U0q5UB2hBY0O/nZFEaEuRLcWpI4EC8vfpRHUWJwhnpzSVP9mzPMaZn85q wOdADL8Z2PS0t7JiewEr4ydIov7o5AuUQ8vvUF7QpctlrpgU6jkUGcr+2k8PMxnoFzw4qDPvT+D j5nE/MFFyq9xLqni1koE1/A7nzpPmIIp2F5YXzi8FghHf1y3tCpWT9oTBfM7miKylBeakGIgkuP KBHT3CTHUCvKQlsZtZH7mFxYy1cdqmTlxMBkHt/r4DEryGUSXue9ogbBerkmshVl4Re6IxN76AM NL03e2hnmIVjAiMBRwgiSuvMrzN37PvdhXrZTJV6Y4AUEjAUxg2e+mNvczZ4Vd7j9f46RqgKkVg Oakl+KORxmUBb21NVIFf3vDb6icw2dqnryZ2FMWmLm8AJzG8Q== X-Received: by 2002:a05:622a:260a:b0:530:b2e2:2f6 with SMTP id d75a77b69052e-5330b705c17mr26762761cf.56.1790324572722; Fri, 25 Sep 2026 01:22:52 -0700 (PDT) Received: from majuu.waya ([184.147.180.207]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-5330c0aae6esm10554481cf.26.2026.09.25.01.22.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 01:22:52 -0700 (PDT) From: Jamal Hadi Salim To: netdev@vger.kernel.org Cc: Jamal Hadi Salim , stable@vger.kernel.org, Jiri Pirko , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Victor Nogueira , Vlad Buslov , Marcelo Ricardo Leitner , hybris , sashiko-bot@kernel.org Subject: [PATCH net 1/2 repost] net/sched: act_api: reject duplicate actions in a batch Date: Fri, 25 Sep 2026 04:22:37 -0400 Message-ID: X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID: <20260925082237.xktTTrRQRmp_V8OKNBxFnnUlj6a452UO12AQPOXYlPc@z> tca_action_gd() builds actions[] with one tcf_action_get_1() per nested TCA_ACT_TAB entry. Each successful lookup takes its own reference to the resolved action, so repeated TCA_ACT_INDEX entries in one request yield the same pointer in multiple slots. For RTM_DELACTION, tcf_action_delete() then consumes two references per slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A duplicate therefore drives the refcount to zero mid-walk -- the delete frees the action and removes its IDR slot -- and the next slot calls tcf_action_put() on the freed action: refcount_t: underflow; use-after-free. WARNING: lib/refcount.c:87 at refcount_dec_not_one refcount_dec_and_mutex_lock __tcf_action_put tca_action_gd Three duplicate entries are enough. Reject a repeated action while a delete batch is built, dropping the reference the extra lookup took, and return -EINVAL. RTM_GETACTION balances its own references and keeps accepting duplicate entries. Conditions to recreate the bug: tc actions add action gact index 100 tc actions delete action gact index 100 action gact index 100 \ action gact index 100 Fixes: 16af6067392c ("net: sched: implement reference counted action release") Reported-by: Sashiko (gemini) Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com Tested-by: hybris Signed-off-by: Jamal Hadi Salim --- net/sched/act_api.c | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/net/sched/act_api.c b/net/sched/act_api.c index e45a63be397c..a9323c42a69a 100644 --- a/net/sched/act_api.c +++ b/net/sched/act_api.c @@ -2026,7 +2026,7 @@ static int tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, u32 portid, int event, struct netlink_ext_ack *extack) { - int i, ret; + int i, j, ret; struct nlattr *tb[TCA_ACT_MAX_PRIO + 1]; struct tc_action *act; size_t attr_size = 0; @@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, ret = PTR_ERR(act); goto err; } + + /* A delete consumes two references per slot (tcf_action_put() + * and tcf_idr_delete_index()) but each entry takes one, so a + * repeated action would hit zero mid-walk. GET balances its + * own references and keeps accepting duplicates. + */ + if (event == RTM_DELACTION) { + for (j = 0; j < i - 1; j++) { + if (actions[j] != act) + continue; + + tcf_action_put(act); + NL_SET_ERR_MSG(extack, + "Duplicate TC action in a delete batch"); + ret = -EINVAL; + goto err; + } + } + attr_size += tcf_action_fill_size(act); actions[i - 1] = act; } -- 2.43.0 From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk2-f13.google.com (mail-qk2-f13.google.com [74.125.230.205]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DEED11A9FA0 for ; Sat, 3 Oct 2026 09:55:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.205 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791021302; cv=none; b=WdIQqJwLGy/w5zKdgeLC0DmT3HBI1ITmUt093yS+KAp41sjhVGFeKQhqenvRajjokcGU4fUnb6nKA49gIb15r2jPJ7FVhbJDRuSMJXrmt2XT1Zx5jQqNYDV92CHPhu1xf+C/QMwIMFwhTKKdq/rNbt+Ims2NkITHtd3xvDVcTJE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791021302; c=relaxed/simple; bh=LWL2mpu5aKq/KWBeDWwk7AH+dZECoiTwjCRx9zv3wlM=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=umCkboRxyLQux2AiT0PIdgBI3bTWFilb07eyln57YTtJxVJodrZJpB3gwXwoTJEJZxB7PKcxZU3HvJKH45bB0ISUr9sqwPtEg4oRRXKTXJZnRzdRWPdmchYr6q4a0vTvQ0iBx13IQ2mVWMXiwJSETuoV+cOvQPYOdoG+tv8aGGA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com; spf=none smtp.mailfrom=mojatatu.com; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b=UKez3Ijo; arc=none smtp.client-ip=74.125.230.205 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=mojatatu.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=mojatatu.com header.i=@mojatatu.com header.b="UKez3Ijo" Received: by mail-qk2-f13.google.com with SMTP id d75a77b69052e-52fb769ca17so1351981cf.2 for ; Sat, 03 Oct 2026 02:55:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mojatatu.com; s=google; t=1791021300; x=1791626100; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=CNeW7Vd7tIlOnNM3yD+vQZMp3opWNzf3Bnh6aL6k2qI=; b=UKez3Ijo/ujA7dJTUFD7JUhCtO4ZpDrVGpzQ0FG4MF6PXwmzjrdg+L7LAgX3+ufz3z Qn+qEB12+KI0Wwjy0DqsDdiQON+gOZ+55gJwLn6SeuQ1KFpVMiB1Om7rU9XH/Ijf1gv4 f/c889fdAdzx08ay8SryNXdQ4y7aLtlCkvY1E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791021300; x=1791626100; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CNeW7Vd7tIlOnNM3yD+vQZMp3opWNzf3Bnh6aL6k2qI=; b=pZ6Io98LjhBLxHzxgXscS+MY3i28AR5wlH6UbcpA/7fJlY77MzQcbhJjXY1urM8TWP ofPXnQNdy+5vWiDvNrVzEBtJIBgkpvuBE2YaMrSkQrMKc7wl0rJ/D2iRPlLRwOcjwsJf 6ZSRJokITwURnNnhMzEGkmEL32D2Zxfl2FdEnLcSYp3LhPpuXo/0ouI45GvpXnBL5hU1 n1onwRonZjWS9YwnNZ7596Oos6GanSYznHbhxnSI9NPq81ln4p1DYE7SXe91nkvXL1FB ddQM7aPxUXRnToB+Ti5hCtXKMCKtneqXpka+m7ttnfVa103yLpXoHYT6CUFsuBjvxgJZ ICeQ== X-Gm-Message-State: AFuF++lQ81TbRzUiOd46ErnlYWSS0KNF/+O4Z2wtk6HOi229H0Rw3Hax I4AZQj6nRWck0U2WfbmMhmMt+9At002ZWhEj85Fk0qzxudBLeyCAQ5vXpQ02h49tzvWNgNwtx3t 17AM= X-Gm-Gg: AYBFou2mq2G/PImPZbmdlLoeAujCikBd+sGSYoWOLocIu1p65AQ7FypBxLXDEXPl0Cx bhAjkxBTkuIxbSmGyWN1gyIiJvtqq09L8DRbAmJZKXY2P18bmJHF9+Mgalu1ir7cpoaVdAxccqu B4oasiphuyqIOXX21icpHNnvAZqdzxFxNoVp4vdgQfh2RcVFrUlbPDWi9VbNs8dO/d2Nmzvy9nv qI6G0jMbIbzLKsKwSLX4kGQKqjLvmZ/IJ6g7uaC+EbI6ug1QkU53MfV7dWPYt27tOy45/oL5dKj AoFjN2Brrl2NqfrAeJHUStOd1yqBzkOzhpn4Hou0QKN3TbqczpSJ6HVMkzFjWH4X+SscB10YMgK FZhJjFI1C7tFLmrCXVuafeLg8nMJDRv6vYXwxoB7r6ytG+Li2ObqoI51oWwT+EPLmPwgDzB9+9u oiV6/zb/YW63GZNh4BO4dTcYP0bDblQur7izSlg6kEWphRAk0/SGysElyjNoNN8s63ImxfD88/f WgWZgcWbi+wO/edaAN9l7yu0h4eIe4eY5SFTYAOVhWXqtvIwD9OPbzWxhjI X-Received: by 2002:a05:622a:610c:b0:533:8900:4eae with SMTP id d75a77b69052e-533cba1ae1emr103536221cf.13.1791021299729; Sat, 03 Oct 2026 02:54:59 -0700 (PDT) Received: from mbili.tail33bf8.ts.net ([64.203.83.2]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-917e0c3e2bdsm40853956d6.49.2026.10.03.02.54.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 02:54:59 -0700 (PDT) From: Jamal Hadi Salim To: netdev@vger.kernel.org Cc: Jamal Hadi Salim , stable@vger.kernel.org, Jiri Pirko , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Victor Nogueira , Vlad Buslov , Marcelo Ricardo Leitner , hybris , sashiko-bot@kernel.org Subject: [PATCH net 1/2 repost2] net/sched: act_api: reject duplicate actions in a batch Date: Sat, 3 Oct 2026 05:54:53 -0400 Message-ID: X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID: <20261003095453.4jiXbPK5mkXck0VOLiLu3sM9l-NGfDiZ4G96YKNDV-0@z> tca_action_gd() builds actions[] with one tcf_action_get_1() per nested TCA_ACT_TAB entry. Each successful lookup takes its own reference to the resolved action, so repeated TCA_ACT_INDEX entries in one request yield the same pointer in multiple slots. For RTM_DELACTION, tcf_action_delete() then consumes two references per slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A duplicate therefore drives the refcount to zero mid-walk -- the delete frees the action and removes its IDR slot -- and the next slot calls tcf_action_put() on the freed action: refcount_t: underflow; use-after-free. WARNING: lib/refcount.c:87 at refcount_dec_not_one refcount_dec_and_mutex_lock __tcf_action_put tca_action_gd Three duplicate entries are enough. Reject a repeated action while a delete batch is built, dropping the reference the extra lookup took, and return -EINVAL. RTM_GETACTION balances its own references and keeps accepting duplicate entries. Conditions to recreate the bug: tc actions add action gact index 100 tc actions delete action gact index 100 action gact index 100 \ action gact index 100 Fixes: 16af6067392c ("net: sched: implement reference counted action release") Reported-by: Sashiko (gemini) Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com Signed-off-by: Jamal Hadi Salim --- net/sched/act_api.c | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/net/sched/act_api.c b/net/sched/act_api.c index e45a63be397c..a9323c42a69a 100644 --- a/net/sched/act_api.c +++ b/net/sched/act_api.c @@ -2026,7 +2026,7 @@ static int tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, u32 portid, int event, struct netlink_ext_ack *extack) { - int i, ret; + int i, j, ret; struct nlattr *tb[TCA_ACT_MAX_PRIO + 1]; struct tc_action *act; size_t attr_size = 0; @@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n, ret = PTR_ERR(act); goto err; } + + /* A delete consumes two references per slot (tcf_action_put() + * and tcf_idr_delete_index()) but each entry takes one, so a + * repeated action would hit zero mid-walk. GET balances its + * own references and keeps accepting duplicates. + */ + if (event == RTM_DELACTION) { + for (j = 0; j < i - 1; j++) { + if (actions[j] != act) + continue; + + tcf_action_put(act); + NL_SET_ERR_MSG(extack, + "Duplicate TC action in a delete batch"); + ret = -EINVAL; + goto err; + } + } + attr_size += tcf_action_fill_size(act); actions[i - 1] = act; } -- 2.43.0