Re: [PATCH net] net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
From: Alexandra Winter
Date: Tue Jul 21 2026 - 10:00:21 EST
On 09.07.26 21:17, Hidayath Khan wrote:
> afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.
> If the allocation fails, nsk is NULL.
>
> The connection-refused path is entered when the listen state check
> fails, the accept backlog is full, or nsk is NULL. The code
> unconditionally calls iucv_sock_kill(nsk) in that path.
>
> iucv_sock_kill() does not accept a NULL socket pointer and immediately
> dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,
> calling iucv_sock_kill(nsk) results in a NULL pointer dereference.
>
> Only call iucv_sock_kill() when a child socket was successfully
> allocated.
>
> Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport")
> Cc: stable@xxxxxxxxxxxxxxx
> Reviewed-by: Alexandra Winter <wintera@xxxxxxxxxxxxx>
> Signed-off-by: Hidayath Khan <hidayath@xxxxxxxxxxxxx>
> ---
> net/iucv/af_iucv.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
> index fed240b453bd..f5b1ec44b6ae 100644
> --- a/net/iucv/af_iucv.c
> +++ b/net/iucv/af_iucv.c
> @@ -1872,7 +1872,8 @@ static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
> afiucv_swap_src_dest(skb);
> trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
> err = dev_queue_xmit(skb);
> - iucv_sock_kill(nsk);
> + if (nsk)
> + iucv_sock_kill(nsk);
> bh_unlock_sock(sk);
> goto out;
> }
>
> base-commit: 262b2eac463d880a664cf92af1107b4f9d84ad37
Gentle ping to netdev maintainers:
Did this one get lost in the overflow?
It is all green in patchwork. Is there something you need us to do?
Should we re-send it?
I don't see this as urgent or especially dangerous.
Kind regards
Alexandra