Re: [PATCH net] bpf: tcp: fix double sock release on batch realloc
From: Jordan Rife
Date: Thu Jul 16 2026 - 19:01:41 EST
On Mon, Jul 13, 2026 at 11:32:30PM +0000, Xiang Mei (Microsoft) wrote:
> bpf_iter_tcp_batch() releases the current batch via
> bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites
> each slot with the socket cookie, then grows the batch. cur_sk/end_sk
> are kept for bpf_iter_tcp_resume(), but on realloc failure the function
> returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over
> slots that now hold cookies rather than sock pointers.
> bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and
> dereferences a cookie as a struct sock.
>
> Empty the batch on the failure path so stop() does not release it
> again. The sockets were already freed by the first
> bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans
Since bpf_iter_tcp_batch returns an ERR_PTR in this case iteration
wouldn't continue on a subsequent read, but otherwise the fix makes
sense to me.
> the bucket from the start instead of skipping it. The sibling
> GFP_NOWAIT failure path still holds real socket references and is left
> for stop() to release.
>
> BUG: KASAN: null-ptr-deref in __sock_gen_cookie
> Read of size 8 at addr 0000000000000059 by task exploit
> ...
> __sock_gen_cookie (net/core/sock_diag.c:28)
> bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)
> bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)
> bpf_seq_read (kernel/bpf/bpf_iter.c:205)
> vfs_read (fs/read_write.c:572)
> ksys_read (fs/read_write.c:716)
> do_syscall_64
> entry_SYSCALL_64_after_hwframe
> Kernel panic - not syncing: Fatal exception
>
> Fixes: cdec67a489d4 ("bpf: tcp: Make sure iter->batch always contains a full bucket snapshot")
> Reported-by: AutonomousCodeSecurity@xxxxxxxxxxxxx
> Signed-off-by: Xiang Mei (Microsoft) <xmei5@xxxxxxx>
> ---
> net/ipv4/tcp_ipv4.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
> index 209ef7522508..dd3ed62704f9 100644
> --- a/net/ipv4/tcp_ipv4.c
> +++ b/net/ipv4/tcp_ipv4.c
> @@ -3141,8 +3141,11 @@ static struct sock *bpf_iter_tcp_batch(struct seq_file *seq)
> bpf_iter_tcp_put_batch(iter);
> err = bpf_iter_tcp_realloc_batch(iter, expected * 3 / 2,
> GFP_USER);
> - if (err)
> + if (err) {
> + iter->cur_sk = 0;
> + iter->end_sk = 0;
> return ERR_PTR(err);
> + }
>
> sk = bpf_iter_tcp_resume(seq);
> if (!sk)
> --
> 2.43.0
>
Reviewed-by: Jordan Rife <jordan@xxxxxxxx>