Re: [PATCH] net/ncsi: Fix Use-After-Free in ncsi_remove_channel/package

Simon Horman <[email protected]>
Newsgroups org.kernel.vger.netdev
Message-ID <[email protected]>
On Thu, Aug 13, 2026 at 12:29:42AM +0800, Wong Boon Jhee wrote:
> From af39fbef05b309b7e183690dbb7e63295ff0be5a Mon Sep 17 00:00:00 2001
> From: Wong Boon Jhee <[email protected]>
> Date: Thu, 13 Aug 2026 00:25:47 +0800
> Subject: [PATCH] net/ncsi: Fix Use-After-Free in NCSI channel and package
>  removal
> 
> In net/ncsi/ncsi-manage.c, ncsi_remove_channel() and
> ncsi_remove_package() remove objects from an RCU-protected linked list
> using list_del_rcu() and immediately free them using kfree().
> 
> Because there is no call to synchronize_rcu() or kfree_rcu(), concurrent
> readers traversing these lists under rcu_read_lock() (such as Netlink
> dump handlers) can still hold a valid pointer to the object. When kfree()
> executes, the reader is left holding a dangling pointer to freed memory,
> resulting in a slab-use-after-free.
> 
> This patch fixes the issue by replacing kfree() with kfree_rcu(), which
> defers the memory freeing until all pre-existing RCU readers have finished
> their critical sections. To support this, a struct rcu_head has been
> added to struct ncsi_channel, struct ncsi_package, and struct ncsi_dev_priv.
> 
> KASAN confirms the freed object belongs to the kmalloc-96 cache, and the
> fix completely eliminates the crash.
> 
> Fixes: 2d283bdd079c ("net/ncsi: Resource management")
> Signed-off-by: Wong Boon Jhee <[email protected]>

Thanks for your patch.
Unfortunately, it does not seem to apply.

Please:

1. Rebase the patch on the current net tree

2. Target that tree when you resubmit the patch

   Subject: [PATCH net v2] ...

3. Include a changelog that describes this change

The b4 tool can help you.

-- 
pw-bot: changes-requested
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.