Re: [PATCH net 1/1] mac802154: fix netdev use-after-free in beacon worker
Miquel Raynal <[email protected]> Tue, 04 Aug 2026 12:40:03 +0200
| Newsgroups | gmane.linux.network |
|---|---|
| Message-ID | <[email protected]> |
On 02/08/2026 at 09:23:34 GMT, Zihan Xi <[email protected]> wrote: > mac802154_beacon_worker() reads local->beacon_req under RCU and derives > the sub-interface from the request, but then drops the RCU read lock and > continues to use both sdata and the embedded wpan_dev. > > mac802154_stop_beacons_locked() cancels only pending beacon work, clears > local->beacon_req and frees the request. A beacon worker that is already > running can therefore continue after interface teardown and dereference > the freed netdev private area. > > The scan worker already pins the netdev before leaving RCU. Apply the > same lifetime rule to the beacon worker: take a netdev reference while > the request is still protected by RCU, and release it on all paths that > continue after the reference is acquired. > > Fixes: 3accf4762734 ("mac802154: Handle basic beaconing") > Cc: [email protected] > Reported-by: Vega <[email protected]> > Assisted-by: Codex:gpt-5.4 > Signed-off-by: Zihan Xi <[email protected]> Looks okay. Reviewed-by: Miquel Raynal <[email protected]> Thanks, Miquèl