mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 10:09:10 +02:00
net/iucv: fix use-after-free of a severed iucv_path
af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sever_path() frees that path with
iucv_path_free() but leaves the notifications queued. A later recvmsg()
drains message_q via iucv_process_message_q() and hands the stale path to
message_receive() -- a use-after-free of the freed iucv_path.
Drop the queued notifications when the path is severed; once the path is
gone they can no longer be received. This also frees the notifications
leaked when a socket is closed with messages still queued.
Fixes: f0703c80e5 ("[AF_IUCV]: postpone receival of iucv-packets")
Closes: https://sashiko.dev/#/patchset/20260705-b4-disp-fc79c0dc-v1-1-d2cdcb57afa9@proton.me?part=1
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260707-b4-disp-783fedbb-v1-1-463b9dbda2ea@proton.me
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
1c975de334
commit
be7cc4656e
|
|
@ -337,6 +337,7 @@ static void iucv_sever_path(struct sock *sk, int with_user_data)
|
|||
unsigned char user_data[16];
|
||||
struct iucv_sock *iucv = iucv_sk(sk);
|
||||
struct iucv_path *path = iucv->path;
|
||||
struct sock_msg_q *p, *n;
|
||||
|
||||
/* Whoever resets the path pointer, must sever and free it. */
|
||||
if (xchg(&iucv->path, NULL)) {
|
||||
|
|
@ -348,6 +349,19 @@ static void iucv_sever_path(struct sock *sk, int with_user_data)
|
|||
} else
|
||||
pr_iucv->path_sever(path, NULL);
|
||||
iucv_path_free(path);
|
||||
|
||||
/*
|
||||
* Message notifications queued on message_q still reference
|
||||
* the now freed path; drop them, otherwise a later recvmsg()
|
||||
* would pass the freed iucv_path to message_receive() via
|
||||
* iucv_process_message_q().
|
||||
*/
|
||||
spin_lock_bh(&iucv->message_q.lock);
|
||||
list_for_each_entry_safe(p, n, &iucv->message_q.list, list) {
|
||||
list_del(&p->list);
|
||||
kfree(p);
|
||||
}
|
||||
spin_unlock_bh(&iucv->message_q.lock);
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user