mirror of
https://github.com/torvalds/linux.git
synced 2026-09-14 16:10:02 +02:00
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
Fixes:
|
||
|---|---|---|
| .. | ||
| af_iucv.c | ||
| iucv.c | ||
| Kconfig | ||
| Makefile | ||