Re: [PATCH net] dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
Alexandra Winter <[email protected]> Wed, 29 Jul 2026 14:25:12 +0200
| Newsgroups | org.kernel.vger.linux-rdma,org.kernel.vger.linux-kernel,org.kernel.vger.linux-s390,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On 27.07.26 11:35, Hidayath Khan wrote: > dibs_lo_attach_dmb(), dibs_lo_detach_dmb() and dibs_lo_unregister_dmb() > look up the dmb_node under dmb_ht_lock, drop the lock and only then > operate on the node's refcount. Nothing keeps the node alive across > that window: __dibs_lo_unregister_dmb() removes the node from the hash > table under the write lock and immediately frees it. > I had lost track of this, but Rahul Chandelkar had already proposed a similar patch [1] for this issue, but never followed up with a v2. Rahul, Hidayath, Would it be ok for both of you to add Reported-by: Rahul Chandelkar <[email protected]> [1] https://lore.kernel.org/netdev/[email protected]/