[PATCH] rxrpc: fix connection reference leak on aborted CHALLENGE
From: Henry Martin
Date: Fri Oct 09 2026 - 08:14:04 EST
rxrpc_process_event() returns -ECONNABORTED before reaching the
CHALLENGE case, skipping the rxrpc_put_connection() that pairs with
the reference rxrpc_post_challenge() stored in sp->chall.conn. The
skb is then freed by the caller while the connection reference stays
held, pinning the connection forever; a malicious server repeating
CHALLENGE-then-ABORT leaks one connection per packet.
Clear sp->chall.conn and put the reference on the aborted path.
Commit 092275882aec4 ("rxrpc: Fix oob challenge leak in cleanup after
notification failure") handled the sibling leak stored by
rxrpc_post_challenge() when its socket notification fails; the
early-return on RXRPC_CONN_ABORTED is the remaining, still-open one.
This vulnerability was discovered by Tencent CodeBuddy Security.
Cc: stable@xxxxxxxxxxxxxxx
Fixes: 5800b1cf3fd8c ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
---
net/rxrpc/conn_event.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/net/rxrpc/conn_event.c b/net/rxrpc/conn_event.c
index 611c790bc6d0..56503a05d5d7 100644
--- a/net/rxrpc/conn_event.c
+++ b/net/rxrpc/conn_event.c
@@ -272,8 +272,20 @@ static int rxrpc_process_event(struct rxrpc_connection *conn,
bool secured = false;
int ret;
- if (conn->state == RXRPC_CONN_ABORTED)
+ if (conn->state == RXRPC_CONN_ABORTED) {
+ /*
+ * Drop the ref taken by rxrpc_post_challenge() on this
+ * CHALLENGE before bailing out: otherwise the skb is
+ * released by the caller with the connection reference
+ * still held, pinning the connection forever (leak).
+ */
+ if (sp->chall.conn) {
+ sp->chall.conn = NULL;
+ rxrpc_put_connection(conn,
+ rxrpc_conn_put_challenge_input);
+ }
return -ECONNABORTED;
+ }
_enter("{%d},{%u,%%%u},", conn->debug_id, sp->hdr.type, sp->hdr.serial);
--
2.43.7