Re: [PATCH net] ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
Norbert Szetei <[email protected]> Wed, 1 Jul 2026 20:03:33 +0200
| Newsgroups | gmane.linux.ppp,gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
On Jul 1, 2026, at 15:25, Sebastian Andrzej Siewior = <[email protected]> wrote: >=20 > On 2026-07-01 14:14:39 [+0200], Norbert Szetei wrote: >> --- a/drivers/net/ppp/ppp_generic.c >> +++ b/drivers/net/ppp/ppp_generic.c >> @@ -184,6 +184,7 @@ struct channel { >> struct list_head clist; /* link in list of channels per unit */ >> spinlock_t upl; /* protects `ppp' and 'bridge' */ >> struct channel __rcu *bridge; /* "bridged" ppp channel */ >> + struct rcu_head rcu; /* for RCU-deferred free of the channel */ >> #ifdef CONFIG_PPP_MULTILINK >> u8 avail; /* flag used in multilink stuff */ >> u8 had_frag; /* >=3D 1 fragments have been sent */ >> @@ -3583,7 +3584,7 @@ static void ppp_release_channel(struct channel = *pch) >> } >> skb_queue_purge(&pch->file.xq); >> skb_queue_purge(&pch->file.rq); >> - kfree(pch); >> + kfree_rcu(pch, rcu); >=20 > =46rom looking at ppp_input(), what ensures that the skb in-flight is = not > added skb_queue which is purged above? Good catch, purging before the free races an in-flight ppp_input() and leaks the skb, confirmed with kmemleak. In v2 I moved the purge into the call_rcu() callback so it runs after the grace period. N. >=20 >> } >=20 > Sebastian