mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
net/smc: fix use-after-free in smc_rx_pipe_buf_release()
smc_rx_splice() hands RMB pages to a pipe and takes a socket reference
per entry so the smc_sock stays alive until the reader finishes. The
connection does not: a concurrent close runs smc_conn_free(), which
releases the receive buffer back to the link group pool.
smc_rx_pipe_buf_release() tests sk_state before taking the socket lock.
The state can change between the test and the lock, and
smc_rx_update_cons() then dereferences conn->rmb_desc and walks
conn->lgr, which smc_conn_free() has already released. On the
is_reg_err path smcr_buf_unuse() frees the descriptor outright, so
this is a use-after-free.
Take the socket lock first and test conn->freed instead.
smc_conn_free() sets that flag before releasing anything, and every
caller holds the socket lock. The two paths exclude each other: either
the pipe release runs first with everything valid, or it sees the flag
and skips the update.
Fixes: 9014db202c ("smc: add support for splice()")
Cc: stable@vger.kernel.org
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260820074642.966856-3-hidayath@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
db51a8658c
commit
c924884743
|
|
@ -115,16 +115,15 @@ static void smc_rx_pipe_buf_release(struct pipe_inode_info *pipe,
|
|||
struct pipe_buffer *buf)
|
||||
{
|
||||
struct smc_spd_priv *priv = (struct smc_spd_priv *)buf->private;
|
||||
struct smc_connection *conn = &priv->smc->conn;
|
||||
struct smc_sock *smc = priv->smc;
|
||||
struct smc_connection *conn;
|
||||
struct sock *sk = &smc->sk;
|
||||
|
||||
if (sk->sk_state == SMC_CLOSED ||
|
||||
sk->sk_state == SMC_PEERFINCLOSEWAIT ||
|
||||
sk->sk_state == SMC_APPFINCLOSEWAIT)
|
||||
goto out;
|
||||
conn = &smc->conn;
|
||||
lock_sock(sk);
|
||||
if (conn->freed) {
|
||||
release_sock(sk);
|
||||
goto out;
|
||||
}
|
||||
smc_rx_update_cons(smc, priv->len);
|
||||
release_sock(sk);
|
||||
if (atomic_sub_and_test(priv->len, &conn->splice_pending))
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user