RE: [PATCH net] tipc: fix infinite loop in __tipc_nl_compat_dumpit

From: Tung Quang Nguyen

Date: Tue Jul 14 2026 - 22:14:49 EST


>Subject: [PATCH net] tipc: fix infinite loop in __tipc_nl_compat_dumpit
>
>cmd->dumpit callback can return a negative errno, causing an infinite
>loop due to the while(len) condition. As the loop never terminates,
>genl_mutex is never released, and other tasks waiting on it starve in D state.
>
>Check dumpit's return value, propagate it and jump to err_out on error.
>
>Reported-by: syzbot+85d0bec020d805014a3a@xxxxxxxxxxxxxxxxxxxxxxxxx
>Closes: https://syzkaller.appspot.com/bug?extid=85d0bec020d805014a3a
>Fixes: d0796d1ef63d ("tipc: convert legacy nl bearer dump to nl compat")
>Signed-off-by: Helen Koike <koike@xxxxxxxxxx>
>---
>
>Tested locally using syzbot reproducer.
>---
> net/tipc/netlink_compat.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
>diff --git a/net/tipc/netlink_compat.c b/net/tipc/netlink_compat.c index
>2a786c56c8c5..d9a4f94ea2d4 100644
>--- a/net/tipc/netlink_compat.c
>+++ b/net/tipc/netlink_compat.c
>@@ -221,6 +221,10 @@ static int __tipc_nl_compat_dumpit(struct
>tipc_nl_compat_cmd_dump *cmd,
> int rem;
>
> len = (*cmd->dumpit)(buf, &cb);
>+ if (len < 0) {
>+ err = len;
>+ goto err_out;
>+ }
>
> nlmsg_for_each_msg(nlmsg, nlmsg_hdr(buf), len, rem) {
> err = nlmsg_parse_deprecated(nlmsg, GENL_HDRLEN,
>--
>2.54.0
>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@xxxxxxxx