Re: [PATCH net v2] ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
Norbert Szetei <[email protected]> Mon, 6 Jul 2026 09:22:55 +0200
| Newsgroups | gmane.linux.ppp,gmane.linux.kernel,gmane.linux.network |
|---|---|
| Message-ID | <[email protected]> |
Hi, > On Jul 3, 2026, at 09:27, Qingfang Deng <[email protected]> = wrote: >=20 > Hi, >=20 > On 2026/7/2 2:12, Norbert Szetei wrote: >> +/* Purge after the grace period: a late ppp_input() may still queue = an >> + * skb on pch->file.rq before the last RCU reader drains. >> + */ >> +static void ppp_release_channel_free(struct rcu_head *rcu) >> +{ >> + struct channel *pch =3D container_of(rcu, struct channel, rcu); >> + >> + skb_queue_purge(&pch->file.xq); >> + skb_queue_purge(&pch->file.rq); >> + kfree(pch); >> +} >> + >> /* >> * Drop a reference to a ppp channel and free its memory if the = refcount reaches >> * zero. >> @@ -3581,9 +3594,7 @@ static void ppp_release_channel(struct channel = *pch) >> pr_err("ppp: destroying undead channel %p !\n", pch); >> return; >> } >> - skb_queue_purge(&pch->file.xq); >> - skb_queue_purge(&pch->file.rq); >> - kfree(pch); >> + call_rcu(&pch->rcu, ppp_release_channel_free); >> } >> static void __exit ppp_cleanup(void) >=20 > AI-review found an issue: = https://sashiko.dev/#/patchset/D9C0245B-608B-4884-8A09-F55BA4A9F948%40doye= nsec.com >=20 > An rcu_barrier() call is needed at the end of ppp_cleanup(). Thanks for reviewing. I'll add it and send out a v3. N. >=20 > Regards, >=20 > Qingfang >=20