Re: [PATCH net v3 2/2] tcp: fix use-after-free in do_tcp_getsockopt(TCP_CC_INFO)
From: Matthieu Baerts
Date: Fri Aug 28 2026 - 05:47:15 EST
On 28/08/2026 01:55, Cen Zhang (Microsoft) wrote:
> From: "Cen Zhang (Microsoft Security FORGE Labs)" <blbllhy@xxxxxxxxx>
>
> do_tcp_getsockopt() reads icsk->icsk_ca_ops and dereferences the
> get_info function pointer without rcu_read_lock(). With BPF struct_ops
> congestion control, ca_ops can point to dynamically allocated memory
> that is freed concurrently, resulting in a use-after-free when the
> kernel dereferences or calls through the stale pointer.
>
> BUG: KASAN: slab-use-after-free in do_tcp_getsockopt+0x2037/0x23e0
> Read of size 8 at addr ffff888013701258 by task exploit/149
> do_tcp_getsockopt+0x2037/0x23e0 (net/ipv4/tcp.c:4564)
> tcp_getsockopt+0x91/0xf0
> __sys_getsockopt+0xf7/0x170
>
> Fix this by wrapping the ca_ops load and get_info call within
> rcu_read_lock()/rcu_read_unlock(), and using READ_ONCE() to load
> the icsk_ca_ops pointer.
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@xxxxxxxxxx>
Cheers,
Matt
--
Sponsored by the NGI0 Core fund.