Re: [PATCH net 2/2] tcp: fix use-after-free in do_tcp_getsockopt(TCP_CC_INFO)
Eric Dumazet <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.bpf,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CANn89iKr1ypEFeL+7te3xWoNaK5AFyYQmr+pDh2zSZAxfgNKjw@mail.gmail.com> |
On Fri, Aug 21, 2026 at 8:25 PM Cen Zhang (Microsoft) <[email protected]> wrote: > > do_tcp_getsockopt() reads icsk->icsk_ca_ops and dereferences the > get_info function pointer without rcu_read_lock(). With BPF struct_ops > congestion control, ca_ops can point to dynamically allocated memory > that is freed concurrently, resulting in a use-after-free when the > kernel dereferences or calls through the stale pointer. > > BUG: KASAN: slab-use-after-free in do_tcp_getsockopt+0x2037/0x23e0 > Read of size 8 at addr ffff888013701258 by task exploit/149 > do_tcp_getsockopt+0x2037/0x23e0 (net/ipv4/tcp.c:4564) > tcp_getsockopt+0x91/0xf0 > __sys_getsockopt+0xf7/0x170 > > Fix this by wrapping the ca_ops load and get_info call within > rcu_read_lock()/rcu_read_unlock(). > > Fixes: 0baf26b0fcd7 ("bpf: tcp: Support tcp_congestion_ops in bpf") > Reported-by: [email protected] > Reported-by: Cen Zhang (Microsoft) <[email protected]> > Cc: [email protected] > Signed-off-by: Cen Zhang (Microsoft) <[email protected]> > --- > The unsynchronized icsk_ca_ops load also constitutes a data race. > READ_ONCE()/WRITE_ONCE() annotations are intentionally left to a > separate change; related TCP annotation work is available at: > https://lore.kernel.org/all/[email protected]/ I don't understand. This patch is incomplete. Please fix the remaining issues in a single patch or series. We have limited time; we don't want to revisit the same area in one month. pw-bot: cr