Re: [PATCH] xfrm: add missing RCU read lock in xfrm_send_migrate_state()

Steffen Klassert <[email protected]>
Newsgroups dev.linux.lists.syzbot,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On Fri, Jul 31, 2026 at 10:06:20AM +0000, syzbot wrote:
> From: Aleksandr Nogikh <[email protected]>
> 
> xfrm_nlmsg_multicast() requires the RCU read lock to be held because it
> safely dereferences the net->xfrm.nlsk pointer using rcu_dereference().
> When it is called from xfrm_send_migrate_state(), the RCU read lock is not
> held, which triggers a suspicious RCU usage warning:
> 
> WARNING: suspicious RCU usage
> net/xfrm/xfrm_user.c:1630 suspicious rcu_dereference_check() usage!
> 
> Call Trace:
>  lockdep_rcu_suspicious+0x13f/0x1d0 kernel/locking/lockdep.c:6876
>  xfrm_nlmsg_multicast+0x1d8/0x1f0 net/xfrm/xfrm_user.c:1630
>  xfrm_send_migrate_state+0x870/0xae0 net/xfrm/xfrm_user.c:3340
>  xfrm_do_migrate_state+0x1749/0x1e90 net/xfrm/xfrm_user.c:3507
>  xfrm_user_rcv_msg+0x7a8/0xf30 net/xfrm/xfrm_user.c:3907
> 
> Fix this by wrapping the xfrm_nlmsg_multicast() call in
> xfrm_send_migrate_state() with rcu_read_lock() and rcu_read_unlock().
> 
> Fixes: a9d155ea9b44 ("xfrm: add XFRM_MSG_MIGRATE_STATE for single SA migration")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=c0e99a1aa85a286d7a3b
> Link: https://syzkaller.appspot.com/ai_job?id=8977f559-3a7e-4bb5-b4d6-1196956260b6
> Signed-off-by: Aleksandr Nogikh <[email protected]>

Applied, thanks a lot!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.