linux/net
Eric Dumazet 9ed55f3dbe net: lock the socket in sock_gettstamp()
sk->sk_flags must only be changed while holding the socket lock,
because sock_set_flag() and sock_reset_flag() use non atomic
operations (__set_bit() and __clear_bit()).

sock_gettstamp() is one of the last places where a bit of sk->sk_flags
is changed from a syscall without owning the socket lock, through
sock_enable_timestamp(sk, SOCK_TIMESTAMP).

sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags
without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.

Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()
can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,
because both threads perform a read-modify-write on the same word.

  CPU 0 (bind)                        CPU 1 (SIOCGSTAMPNS_NEW)
  --------------------------------    ----------------------------
  read sk_flags = F                   read sk_flags = F
  compute F | BIT(SOCK_RCU_FREE)      compute F | BIT(SOCK_TIMESTAMP)
  store F | BIT(SOCK_RCU_FREE)
  sk_add_node_rcu(sk, ...)
                                      store F | BIT(SOCK_TIMESTAMP)

After the lost update, SOCK_RCU_FREE is clear while the socket is
visible to lockless UDP receive lookups. sk_destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:

 BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410
 Read of size 8 at addr ffff888008806610 by task exploit/207
 CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
  ipv4_pktinfo_prepare+0x30/0x410
  udp_queue_rcv_one_skb+0x51c/0x1180
  udp_unicast_rcv_skb+0x109/0x350
  ip_protocol_deliver_rcu+0x14b/0x310
  ip_local_deliver_finish+0x29d/0x390
  ip_local_deliver+0x24d/0x2a0

Only grab the socket lock when SOCK_TIMESTAMP has to be set,
to keep the common case lockless.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Reported-by: Jungwoo Lee <jwlee2217@gmail.com>
Reported-by: Wongi Lee <qw3rtyp0@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-16 17:34:56 -07:00
..
6lowpan net: 6lowpan: fix mismatched comments 2026-09-02 09:03:06 +02:00
9p 9p: Add missing read barrier in virtio zero-copy path 2026-06-21 05:22:57 +00:00
802 appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
8021q vlan: fix skb_under_panic and races when toggling HW VLAN offload 2026-08-20 13:05:43 -07:00
atm pppoatm: ensure a writable skb header and linear data 2026-09-15 17:07:01 -07:00
batman-adv treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
bluetooth Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup 2026-09-15 14:55:41 -04:00
bpf bpf: Fix partial copy of non-linear test_run output 2026-06-21 17:55:06 -07:00
bridge net: bridge: vlan: fix bugs caused by switchdev deletion errors 2026-09-15 18:31:57 -07:00
can can: isotp: check register_netdevice_notifier() error in module init 2026-07-29 11:26:41 +02:00
ceph libceph: remove pinning assertion in ceph_msg_data_iter_next() 2026-09-02 12:23:05 +02:00
core net: lock the socket in sock_gettstamp() 2026-09-16 17:34:56 -07:00
dcb
devlink treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
dns_resolver keys, dns: Drop unused NUL terminator from upayload->data 2026-08-10 16:20:42 -07:00
dsa net: dsa: tag_brcm: legacy FCS: request needed tailroom 2026-09-09 13:31:08 -07:00
ethernet
ethtool ethtool: tsconfig: reject zero-valued tx_type and rx_filter bitsets 2026-08-13 17:44:54 -07:00
handshake handshake: Require admin permission for DONE command 2026-06-12 15:45:44 -07:00
hsr net: hsr: enable promiscuous mode on interlink port with fwd offload 2026-09-10 08:45:00 -07:00
ieee802154 ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink 2026-09-02 09:54:27 +02:00
ife net/sched: act_ife: Only operate on Ethernet frames 2026-08-24 11:59:59 -07:00
ipv4 ipsec-2026-09-16 2026-09-16 15:54:19 -07:00
ipv6 ipsec-2026-09-16 2026-09-16 15:54:19 -07:00
iucv net/iucv: fix the recvmsg window update 2026-08-31 15:51:22 -07:00
kcm net: kcm: Hold RCU read lock while running BPF parser 2026-08-17 13:43:58 -07:00
key ipsec-2026-06-22 2026-06-23 16:22:24 -07:00
l2tp net: l2tp: do not propagate multicast notification errors 2026-08-24 11:43:28 -07:00
l3mdev
lapb
llc llc: fix SAP refcount leak when creating incoming sockets 2026-07-17 13:17:46 +02:00
mac80211 Many fixes: 2026-09-16 15:54:56 -07:00
mac802154 mac802154: fix use-after-free of sdata via queued RX frames 2026-09-03 11:00:54 +02:00
mctp treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
mpls Summary 2026-08-20 08:46:41 -07:00
mptcp mptcp: return sk_wait_data() errors from recvmsg() 2026-09-16 17:28:06 -07:00
ncsi net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length 2026-08-05 17:24:57 -07:00
netfilter netfilter: flowtable: hold reference on ct until flow is released 2026-09-11 13:04:15 +02:00
netlabel Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-06-11 14:33:35 -07:00
netlink netlink: do not free nlk->groups while lockless readers can use it 2026-09-15 18:44:02 -07:00
nfc nfc: nci: free destination parameters when closing a connection 2026-08-11 18:10:04 +02:00
nsh
openvswitch openvswitch: avoid reallocating confirmed conntrack labels 2026-09-15 18:00:46 -07:00
packet net/packet: avoid truncating TPACKET_V3 private size 2026-09-16 17:29:11 -07:00
phonet phonet: pep: convert getsockopt to sockopt_t 2026-08-03 16:55:23 -07:00
psample net: psample: fix info leak in PSAMPLE_ATTR_DATA 2026-06-17 16:35:50 -07:00
psp psp: use unrcu_pointer() for the cmpxchg() on netdev psp_dev 2026-08-17 11:06:14 -07:00
qrtr net: qrtr: Send HELLO message on endpoint register 2026-09-02 12:14:32 +01:00
rds rds: ib: use rds_conn_drop() on protocol version mismatch 2026-09-14 18:47:52 -07:00
rfkill Replace <linux/mod_devicetable.h> by more specific <linux/device-id/*.h> (c files) 2026-07-03 07:38:17 +02:00
rxrpc treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
sched net/sched: act_api: release tail references on DELACTION failure 2026-09-15 17:03:09 -07:00
sctp sctp: validate chunk length in the inqueue parser 2026-08-30 14:17:53 -07:00
shaper net: shaper: add a note that we expect cap dumps to be tiny 2026-06-11 12:55:23 +02:00
smc Including fixes from Bluetooth, IPSec and Netfilter. 2026-08-27 13:53:43 -07:00
strparser
sunrpc treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
switchdev
tipc tipc: Dont send random pad bytes in RESET/ACTIVATE messages 2026-08-31 20:02:36 -07:00
tls tls: device: fix out-of-bounds write in tls_append_frag() 2026-08-25 10:04:02 +02:00
unix af_unix: Unify scc_index when finalising SCC in __unix_walk_scc(). 2026-09-15 16:45:05 -07:00
vmw_vsock vsock/vmci: validate packet source for connected sockets 2026-08-31 16:50:54 -07:00
wireless Many fixes: 2026-09-16 15:54:56 -07:00
x25 net/x25: fix use-after-free of the socket by its timers 2026-07-30 18:46:45 -07:00
xdp xsk: honor XDP_TX_METADATA in zero-copy path 2026-08-24 11:12:00 -07:00
xfrm ipsec-2026-09-16 2026-09-16 15:54:19 -07:00
compat.c net: af_unix: useful handling of LSM denials on SCM_RIGHTS 2026-08-17 18:14:52 -07:00
devres.c
Kconfig appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
Kconfig.debug
Makefile appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
socket.c Major changes: 2026-08-20 07:36:20 -07:00
sysctl_net.c net: enforce net sysctl registration 2026-08-13 13:12:21 +02:00