RE: [Intel-wired-lan] [PATCH net v2] ice: eswitch: fix use-after-free of metadata_dst in repr release

"Holda, Patryk" <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.osuosl.intel-wired-lan
Message-ID <IA3PR11MB93019BFA8437C98A13F00DCA8ADB2@IA3PR11MB9301.namprd11.prod.outlook.com>
> -----Original Message-----
> From: Intel-wired-lan <[email protected]> On Behalf Of
> Marcin Szycik
> Sent: Wednesday, June 24, 2026 1:36 PM
> To: Doruk Tan Ozturk <[email protected]>; Nguyen, Anthony L
> <[email protected]>; Kitszel, Przemyslaw
> <[email protected]>; [email protected];
> [email protected]; [email protected]; [email protected];
> [email protected]
> Cc: [email protected]; Drewek, Wojciech
> <[email protected]>; [email protected];
> [email protected]; [email protected];
> [email protected]; [email protected]
> Subject: Re: [Intel-wired-lan] [PATCH net v2] ice: eswitch: fix use-after-free of
> metadata_dst in repr release
> Importance: High
> 
> 
> 
> On 18/06/2026 16:50, Doruk Tan Ozturk wrote:
> > ice_eswitch_release_repr() frees the port representor metadata_dst via
> > metadata_dst_free(), which directly kfree()s the object and ignores
> > the dst_entry refcount. The eswitch slow-path TX routine
> > ice_eswitch_port_start_xmit() takes a reference on this dst with
> > dst_hold() and attaches it to the skb via skb_dst_set(). If such an
> > skb is still in flight (e.g. queued in a qdisc) when the representor
> > is torn down, the metadata_dst is freed while the skb still points at
> > it. When the skb is later freed, dst_release() operates on already-freed
> memory.
> >
> > Replace metadata_dst_free() with dst_release() so the metadata_dst is
> > freed only after the last reference is dropped. The dst subsystem
> > frees metadata_dst objects from dst_destroy() once the refcount
> > reaches zero (DST_METADATA is set by metadata_dst_alloc()).
> >
> > Same class of bug and fix as commit c32b26aaa2f9 ("netfilter:
> > nft_tunnel: fix use-after-free on object destroy").
> >
> > Fixes: 1a1c40df2e80 ("ice: set and release switchdev environment")
> > Cc: [email protected]
> > Signed-off-by: Doruk Tan Ozturk <[email protected]>
> > Reviewed-by: Simon Horman <[email protected]>
> 
> Reviewed-by: Marcin Szycik <[email protected]>
> 
> > ---
> > v2:
> >  - Correct the Fixes: tag to 1a1c40df2e80 ("ice: set and release
> >    switchdev environment"); the previously cited fff292b47ac1 only moved
> >    the affected code rather than introducing the unbalanced free, and the
> >    bug dates back to when switchdev support was added (Simon Horman).
> >  - Add Simon Horman's Reviewed-by. No functional change.
> >
> >  drivers/net/ethernet/intel/ice/ice_eswitch.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/net/ethernet/intel/ice/ice_eswitch.c
> > b/drivers/net/ethernet/intel/ice/ice_eswitch.c
> > index 2e4f0969035f..41b30a7ca4a9 100644
> > --- a/drivers/net/ethernet/intel/ice/ice_eswitch.c
> > +++ b/drivers/net/ethernet/intel/ice/ice_eswitch.c
> > @@ -95,7 +95,7 @@ ice_eswitch_release_repr(struct ice_pf *pf, struct
> ice_repr *repr)
> >  		return;
> >
> >  	ice_vsi_update_security(vsi, ice_vsi_ctx_set_antispoof);
> > -	metadata_dst_free(repr->dst);
> > +	dst_release(&repr->dst->dst);
> >  	repr->dst = NULL;
> >  	ice_fltr_add_mac_and_broadcast(vsi, repr->parent_mac,
> >  				       ICE_FWD_TO_VSI);
> > --
> > 2.43.0


Tested-by: Patryk Holda <[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.