RE: [Intel-wired-lan] [PATCH net v2] ice: eswitch: fix use-after-free of metadata_dst in repr release
"Holda, Patryk" <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.osuosl.intel-wired-lan |
|---|---|
| Message-ID | <IA3PR11MB93019BFA8437C98A13F00DCA8ADB2@IA3PR11MB9301.namprd11.prod.outlook.com> |
> -----Original Message----- > From: Intel-wired-lan <[email protected]> On Behalf Of > Marcin Szycik > Sent: Wednesday, June 24, 2026 1:36 PM > To: Doruk Tan Ozturk <[email protected]>; Nguyen, Anthony L > <[email protected]>; Kitszel, Przemyslaw > <[email protected]>; [email protected]; > [email protected]; [email protected]; [email protected]; > [email protected] > Cc: [email protected]; Drewek, Wojciech > <[email protected]>; [email protected]; > [email protected]; [email protected]; > [email protected]; [email protected] > Subject: Re: [Intel-wired-lan] [PATCH net v2] ice: eswitch: fix use-after-free of > metadata_dst in repr release > Importance: High > > > > On 18/06/2026 16:50, Doruk Tan Ozturk wrote: > > ice_eswitch_release_repr() frees the port representor metadata_dst via > > metadata_dst_free(), which directly kfree()s the object and ignores > > the dst_entry refcount. The eswitch slow-path TX routine > > ice_eswitch_port_start_xmit() takes a reference on this dst with > > dst_hold() and attaches it to the skb via skb_dst_set(). If such an > > skb is still in flight (e.g. queued in a qdisc) when the representor > > is torn down, the metadata_dst is freed while the skb still points at > > it. When the skb is later freed, dst_release() operates on already-freed > memory. > > > > Replace metadata_dst_free() with dst_release() so the metadata_dst is > > freed only after the last reference is dropped. The dst subsystem > > frees metadata_dst objects from dst_destroy() once the refcount > > reaches zero (DST_METADATA is set by metadata_dst_alloc()). > > > > Same class of bug and fix as commit c32b26aaa2f9 ("netfilter: > > nft_tunnel: fix use-after-free on object destroy"). > > > > Fixes: 1a1c40df2e80 ("ice: set and release switchdev environment") > > Cc: [email protected] > > Signed-off-by: Doruk Tan Ozturk <[email protected]> > > Reviewed-by: Simon Horman <[email protected]> > > Reviewed-by: Marcin Szycik <[email protected]> > > > --- > > v2: > > - Correct the Fixes: tag to 1a1c40df2e80 ("ice: set and release > > switchdev environment"); the previously cited fff292b47ac1 only moved > > the affected code rather than introducing the unbalanced free, and the > > bug dates back to when switchdev support was added (Simon Horman). > > - Add Simon Horman's Reviewed-by. No functional change. > > > > drivers/net/ethernet/intel/ice/ice_eswitch.c | 2 +- > > 1 file changed, 1 insertion(+), 1 deletion(-) > > > > diff --git a/drivers/net/ethernet/intel/ice/ice_eswitch.c > > b/drivers/net/ethernet/intel/ice/ice_eswitch.c > > index 2e4f0969035f..41b30a7ca4a9 100644 > > --- a/drivers/net/ethernet/intel/ice/ice_eswitch.c > > +++ b/drivers/net/ethernet/intel/ice/ice_eswitch.c > > @@ -95,7 +95,7 @@ ice_eswitch_release_repr(struct ice_pf *pf, struct > ice_repr *repr) > > return; > > > > ice_vsi_update_security(vsi, ice_vsi_ctx_set_antispoof); > > - metadata_dst_free(repr->dst); > > + dst_release(&repr->dst->dst); > > repr->dst = NULL; > > ice_fltr_add_mac_and_broadcast(vsi, repr->parent_mac, > > ICE_FWD_TO_VSI); > > -- > > 2.43.0 Tested-by: Patryk Holda <[email protected]>