Re: [PATCH net v2 2/2] tcp: fix use-after-free in do_tcp_getsockopt(TCP_CC_INFO)
From: Eric Dumazet
Date: Wed Aug 26 2026 - 13:41:59 EST
On Wed, Aug 26, 2026 at 7:14 PM Cen Zhang (Microsoft) <blbllhy@xxxxxxxxx> wrote:
>
> From: "Cen Zhang (Microsoft Security FORGE Labs)" <blbllhy@xxxxxxxxx>
>
> do_tcp_getsockopt() reads icsk->icsk_ca_ops and dereferences the
> get_info function pointer without rcu_read_lock(). With BPF struct_ops
> congestion control, ca_ops can point to dynamically allocated memory
> that is freed concurrently, resulting in a use-after-free when the
> kernel dereferences or calls through the stale pointer.
>
> BUG: KASAN: slab-use-after-free in do_tcp_getsockopt+0x2037/0x23e0
> Read of size 8 at addr ffff888013701258 by task exploit/149
> do_tcp_getsockopt+0x2037/0x23e0 (net/ipv4/tcp.c:4564)
> tcp_getsockopt+0x91/0xf0
> __sys_getsockopt+0xf7/0x170
>
> Fix this by wrapping the ca_ops load and get_info call within
> rcu_read_lock()/rcu_read_unlock(), and using READ_ONCE() to load
> the icsk_ca_ops pointer.
>
Reviewed-by: Eric Dumazet <edumazet@xxxxxxxxxx>
Thanks.