Re: [PATCH net 1/1] mac802154: fix netdev use-after-free in beacon worker

Miquel Raynal <[email protected]> Tue, 04 Aug 2026 12:40:03 +0200
Newsgroups gmane.linux.network
Message-ID <[email protected]>
On 02/08/2026 at 09:23:34 GMT, Zihan Xi <[email protected]> wrote:

> mac802154_beacon_worker() reads local->beacon_req under RCU and derives
> the sub-interface from the request, but then drops the RCU read lock and
> continues to use both sdata and the embedded wpan_dev.
>
> mac802154_stop_beacons_locked() cancels only pending beacon work, clears
> local->beacon_req and frees the request.  A beacon worker that is already
> running can therefore continue after interface teardown and dereference
> the freed netdev private area.
>
> The scan worker already pins the netdev before leaving RCU.  Apply the
> same lifetime rule to the beacon worker: take a netdev reference while
> the request is still protected by RCU, and release it on all paths that
> continue after the reference is acquired.
>
> Fixes: 3accf4762734 ("mac802154: Handle basic beaconing")
> Cc: [email protected]
> Reported-by: Vega <[email protected]>
> Assisted-by: Codex:gpt-5.4
> Signed-off-by: Zihan Xi <[email protected]>

Looks okay.

Reviewed-by: Miquel Raynal <[email protected]>

Thanks,
Miquèl