Re: [PATCH bpf v3 0/2] bpf: Fix socket leaks around connect(AF_UNSPEC)+listen()

Kuniyuki Iwashima <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.kernel.bpf,gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel
Message-ID <CAAVpQUC==6KEBs3XgFjZ536mJ23cbHma8HuiWMu1DRc_=YYOHg@mail.gmail.com>
On Wed, Sep 2, 2026 at 10:55 AM Michal Luczaj <[email protected]> wrote:
>
> This is a follow-up to Sashiko's report[1].
>
> Several BPF socket helpers acquire a socket reference only when
> sk_is_refcounted() == true, and release it, independently, by
> re-evaluating sk_is_refcounted() again at the time the release runs. TCP
> connect(AF_UNSPEC)+listen() sets SOCK_RCU_FREE on an established socket.

Due to several bug reports, we are now inclined to forbid the
buggy transformation.
https://lore.kernel.org/netdev/CANn89i+px52TtJy3S9=uHxGj3s-WueguRo1Z_4FxO=02KLmwmQ@mail.gmail.com/


> If that happens while a reference is outstanding, the release side sees
> sk_is_refcounted() == false and skips the put; the socket is leaked.
>
> unreferenced object 0xffff88811617ce00 (size 3200):
>   comm "softirq", pid 0, jiffies 4294848512
>   hex dump (first 32 bytes):
>     7f 00 00 01 7f 00 00 01 4d 43 02 f6 00 00 00 00  ........MC......
>     02 00 07 41 00 00 00 00 00 00 00 00 00 00 00 00  ...A............
>   backtrace (crc fb5bd4c8):
>     kmem_cache_alloc_noprof+0x53e/0x640
>     sk_prot_alloc+0x69/0x240
>     sk_clone+0x79/0x1230
>     inet_csk_clone_lock+0x30/0x760
>     tcp_create_openreq_child+0x34/0x2750
>     tcp_v4_syn_recv_sock+0x12e/0x1080
>     tcp_check_req+0x447/0x2310
>     tcp_v4_rcv+0x1026/0x3c90
>     ip_protocol_deliver_rcu+0x93/0x340
>     ip_local_deliver_finish+0x356/0x5c0
>     ip_local_deliver+0x184/0x4a0
>     ip_rcv+0x4f4/0x5b0
>     __netif_receive_skb_one_core+0x153/0x1b0
>     process_backlog+0x28d/0x1190
>     __napi_poll+0xab/0x520
>     net_rx_action+0x3f0/0xca0
>
> [1]: https://lore.kernel.org/bpf/[email protected]/
>
> Signed-off-by: Michal Luczaj <[email protected]>
> ---
> Changes in v3:
> - Add a fix for TC bpf_sk_assign() (patch #2)
> - Clean up commit messages
> - Non-fixes went to bpf-next: https://lore.kernel.org/bpf/[email protected]/
> - Link to v2: https://patch.msgid.link/[email protected]
>
> Changes in v2:
> - Defer "Use sock_hold() instead of refcount_inc_not_zero() in lookup" to
>   bpf-next [John]
> - Fix comment style [Sashiko]
> - Link to v1: https://patch.msgid.link/[email protected]
>
> To: Alexei Starovoitov <[email protected]>
> To: Daniel Borkmann <[email protected]>
> To: Andrii Nakryiko <[email protected]>
> To: Eduard Zingerman <[email protected]>
> To: Kumar Kartikeya Dwivedi <[email protected]>
> To: Martin KaFai Lau <[email protected]>
> To: Song Liu <[email protected]>
> To: Yonghong Song <[email protected]>
> To: Jiri Olsa <[email protected]>
> To: Emil Tsalapatis <[email protected]>
> To: John Fastabend <[email protected]>
> To: Stanislav Fomichev <[email protected]>
> To: "David S. Miller" <[email protected]>
> To: Eric Dumazet <[email protected]>
> To: Jakub Kicinski <[email protected]>
> To: Paolo Abeni <[email protected]>
> To: Simon Horman <[email protected]>
> To: Kuniyuki Iwashima <[email protected]>
> To: Willem de Bruijn <[email protected]>
> To: Jakub Sitnicki <[email protected]>
> To: Jiayuan Chen <[email protected]>
> To: Joe Stringer <[email protected]>
> To: Ihor Solodrai <[email protected]>
> To: Pablo Neira Ayuso <[email protected]>
> To: Florian Westphal <[email protected]>
> To: Phil Sutter <[email protected]>
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
>
> ---
> Michal Luczaj (2):
>       bpf: Unconditionally take socket references in lookup helpers
>       bpf: Fix reference leak in bpf_sk_assign()
>
>  include/net/inet6_hashtables.h |  9 ++++----
>  include/net/inet_hashtables.h  |  9 ++++----
>  include/net/request_sock.h     |  2 +-
>  include/net/sock.h             | 11 ++++++++++
>  net/core/filter.c              | 49 +++++++++++++++++++++++++++++-------------
>  net/core/sock_map.c            |  8 ++-----
>  net/netfilter/nf_queue.c       | 18 ++++++++--------
>  7 files changed, 67 insertions(+), 39 deletions(-)
> ---
> base-commit: ce6b9e5dd873de532cd924e2abc928220cdc2738
> change-id: 20260628-sockmap-lookup-tcp-leak-bdaba3e083c5
>
> Best regards,
> --
> Michal Luczaj <[email protected]>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.