Re: [PATCH] net/ncsi: Fix Use-After-Free in ncsi_remove_channel/package
Simon Horman <[email protected]>
| Newsgroups | org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Aug 13, 2026 at 12:29:42AM +0800, Wong Boon Jhee wrote: > From af39fbef05b309b7e183690dbb7e63295ff0be5a Mon Sep 17 00:00:00 2001 > From: Wong Boon Jhee <[email protected]> > Date: Thu, 13 Aug 2026 00:25:47 +0800 > Subject: [PATCH] net/ncsi: Fix Use-After-Free in NCSI channel and package > removal > > In net/ncsi/ncsi-manage.c, ncsi_remove_channel() and > ncsi_remove_package() remove objects from an RCU-protected linked list > using list_del_rcu() and immediately free them using kfree(). > > Because there is no call to synchronize_rcu() or kfree_rcu(), concurrent > readers traversing these lists under rcu_read_lock() (such as Netlink > dump handlers) can still hold a valid pointer to the object. When kfree() > executes, the reader is left holding a dangling pointer to freed memory, > resulting in a slab-use-after-free. > > This patch fixes the issue by replacing kfree() with kfree_rcu(), which > defers the memory freeing until all pre-existing RCU readers have finished > their critical sections. To support this, a struct rcu_head has been > added to struct ncsi_channel, struct ncsi_package, and struct ncsi_dev_priv. > > KASAN confirms the freed object belongs to the kmalloc-96 cache, and the > fix completely eliminates the crash. > > Fixes: 2d283bdd079c ("net/ncsi: Resource management") > Signed-off-by: Wong Boon Jhee <[email protected]> Thanks for your patch. Unfortunately, it does not seem to apply. Please: 1. Rebase the patch on the current net tree 2. Target that tree when you resubmit the patch Subject: [PATCH net v2] ... 3. Include a changelog that describes this change The b4 tool can help you. -- pw-bot: changes-requested