mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 12:34:02 +02:00
net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put
In mlx5_eswitch_termtbl_put(), the zero-ref cleanup check reads
tt->ref_count after termtbl_mutex has been released. Two concurrent
callers on the same mlx5_termtbl_handle race: one decrements ref_count
to zero, removes the hash entry, and calls kfree(tt) while the other
has already dropped the mutex and is about to evaluate
if (!tt->ref_count), producing a use-after-free.
Fix this by capturing the result of the decrement into a stack-local
last variable before dropping the mutex. The cleanup decision is now
made entirely under termtbl_mutex, and tt is not touched after
kfree.
Fixes: 10caabdaad ("net/mlx5e: Use termination table for VLAN push actions")
Signed-off-by: Yael Chemla <ychemla@nvidia.com>
Reviewed-by: Dragos Tatulea <dtatulea@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902193514.3668880-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
af3aef0245
commit
7ee07f601f
|
|
@ -163,12 +163,15 @@ void
|
|||
mlx5_eswitch_termtbl_put(struct mlx5_eswitch *esw,
|
||||
struct mlx5_termtbl_handle *tt)
|
||||
{
|
||||
bool last;
|
||||
|
||||
mutex_lock(&esw->offloads.termtbl_mutex);
|
||||
if (--tt->ref_count == 0)
|
||||
last = (--tt->ref_count == 0);
|
||||
if (last)
|
||||
hash_del(&tt->termtbl_hlist);
|
||||
mutex_unlock(&esw->offloads.termtbl_mutex);
|
||||
|
||||
if (!tt->ref_count) {
|
||||
if (last) {
|
||||
mlx5_del_flow_rules(tt->rule);
|
||||
mlx5_destroy_flow_table(tt->termtbl);
|
||||
kfree(tt);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user