Re: [PATCH net v4] nfc: nci: Fix conn_info use-after-free

David Heidelberg <[email protected]>
Newsgroups dev.linux.lists.oe-linux-nfc,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On 23/07/2026 04:24, Sanghyun Park wrote:
> nci_tx_work() looks up conn_info from conn_info_list and keeps using
> that pointer while sending queued data. nci_core_conn_close_rsp_packet()
> runs on the separate rx_wq and can remove and free the same conn_info,
> so the tx worker can dereference freed memory.
> 
> The same lifetime rule also has to cover other conn_info_list users and
> the direct rf_conn_info and hci_dev->conn_info aliases. Protect
> conn_info_list and conn_info pointer aliases with a dedicated lock, use
> it while publishing and removing entries, and keep readers under the lock
> while they dereference conn_info or copy the fields they need.
> 
> In nci_tx_work(), take the lock only around lookup, credit checks, skb
> dequeue, and credit accounting so close cannot free conn_info while it is
> used, but transport send latency does not block rx_wq response
> processing.
> 
> Fixes: 736bb9577407 ("NFC: nci: Support logical connections management")
> Signed-off-by: Sanghyun Park <[email protected]>
> ---
> v4:
>    - Guard hci_dev before clearing its conn_info alias during teardown.
>    - Reflow lines flagged by the netdev 80-column check.
>    - Use the current NFC maintainer address from MAINTAINERS.
> v3: https://lore.kernel.org/netdev/[email protected]/
>    - Add Fixes tag for the logical connection close lifetime bug.
>    - Add the missing NFC maintainer and oe-linux-nfc list.
>    - Cover all conn_info_list helper users, not only nci_tx_work().
>    - Protect direct rf_conn_info and hci_dev->conn_info aliases.
>    - Publish and remove conn_info entries under the same lock.
>    - Protect RF conn_info discovery publication with the same lock.
>    - Keep HCI rx_skb immediate dereferences under conn_info_lock.
>    - Narrow nci_send_data() lock coverage around skb queueing.
>    - Avoid holding conn_info_lock across nci_send_frame().
>    - Use spin_lock_bh() so HCI timer callbacks do not take a sleepable lock.
>    - Keep conn_info_lock alive until nci_dev teardown instead of destroying it before nfc_remove_device().
> v2: https://patchwork.kernel.org/project/netdevbpf/patch/[email protected]/
>    - Replace flush-only fix with conn_info locking around tx and close.
> v1: https://patchwork.kernel.org/project/netdevbpf/patch/CAOrxSK5UmFFfzdRG+P89+E+Rvg_1DmOvTs+M7353Q8=hkPXmSg@mail.gmail.com/
> 
>   drivers/nfc/st-nci/se.c    |  16 +++---
>   include/net/nfc/nci_core.h |   9 ++-
>   net/nfc/nci/core.c         |  98 +++++++++++++++++++++++++--------
>   net/nfc/nci/data.c         |  68 ++++++++++++++---------
>   net/nfc/nci/hci.c          | 109 +++++++++++++++++++++++++++++--------
>   net/nfc/nci/ntf.c          |  23 ++++++--
>   net/nfc/nci/rsp.c          |  52 +++++++++++++-----
>   7 files changed, 271 insertions(+), 104 deletions(-)
> 
Hello Sanghyun,

thank you for the patch, LGMT. Could you please rebase against

https://codeberg.org/linux-nfc/linux/src/branch/for-linus

There is a small conflict in the rsp.c

Thanks!
David
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.