Re: [PATCH net v3] gtp: serialize PDP context updates
Pablo Neira Ayuso <[email protected]>
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <anrpdUa_ngVKH6NR@chamomile> |
On Tue, Aug 11, 2026 at 10:20:12AM +0800, Qing Ming wrote:
> PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
> network device is being unregistered. The latter is serialized by RTNL,
> but the generic-netlink delete path only holds RCU.
>
> Running both paths concurrently can therefore make both paths delete the
> same PDP context. The issue was found through static analysis and
> reproduced on a KASAN-enabled kernel by a two-thread program
> racing GTP_CMD_DELPDP against RTM_DELLINK:
>
> Oops: general protection fault, probably for non-canonical address
> KASAN: maybe wild-memory-access in range
> [0xdead000000000120-0xdead000000000127]
> RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]
> RBP: dead000000000122
>
> The second deletion dereferenced the poisoned hlist pprev pointer.
>
> Serialize PDP context updates with a mutex shared by gtp_pdp_add(),
> gtp_genl_del_pdp(), and gtp_dellink().
>
> Fixes: 459aa660eb1d ("gtp: add initial driver for datapath of GPRS Tunneling Protocol (GTP-U)")
> Assisted-by: Codex:gpt-5
> Signed-off-by: Qing Ming <[email protected]>
> ---
> v3:
> - Rebase onto net/main.
>
> v2: https://lore.kernel.org/netdev/[email protected]/
> - Use a dedicated mutex instead of RTNL.
> - Protect PDP add, delete, and link teardown with the same mutex.
>
> drivers/net/gtp.c | 9 +++++++++
> 1 file changed, 9 insertions(+)
>
> diff --git a/drivers/net/gtp.c b/drivers/net/gtp.c
> index 9a12cc53da00..8ee516debeed 100644
> --- a/drivers/net/gtp.c
> +++ b/drivers/net/gtp.c
[...]
> @@ -2134,6 +2140,8 @@ static int gtp_genl_del_pdp(struct sk_buff *skb, struct genl_info *info)
> if (!info->attrs[GTPA_VERSION])
> return -EINVAL;
>
> + mutex_lock(>p_pdp_lock);
> +
> rcu_read_lock();
This rcu_read_lock() can go away after adding this new mutex.
> pctx = gtp_find_pdp(sock_net(skb->sk), info->attrs);
> @@ -2154,6 +2162,7 @@ static int gtp_genl_del_pdp(struct sk_buff *skb, struct genl_info *info)
>
> out_unlock:
> rcu_read_unlock();
This can go away too, for gtp_genl_del_pdp(), the mutex replaces this
incorrect rcu read size lock.
Thanks.
> + mutex_unlock(>p_pdp_lock);
> return err;
> }
>
> --
> 2.53.0
>