[PATCH net v2 0/1] net/sched: defer qdisc freeing after failed creation
From: Weiming Shi
Date: Wed Sep 02 2026 - 12:02:43 EST
This is v2 of the qdisc failed-creation lifetime fix posted by Kyle Zeng
and David Lee [1]. The public reproducer is available in a follow-up
message [2].
When clsact binds a populated shared ingress block, ->init() can publish
an embedded mini_Qdisc before qdisc_create() completes. A later invalid
TCA_RATE makes estimator setup fail. The unwind removes the published
pointer but frees the containing qdisc synchronously while tc_run() can
still hold it.
The fix itself is unchanged: failed qdiscs are retired through RCU.
With the public reproducer from [2], the vulnerable kernel reports a
KASAN UAF in tc_run(), with the free in qdisc_create(). The same test
completes without a KASAN report on v2.
Changes in v2:
- inline qdisc_free() into qdisc_free_cb()
- use qdisc_free_rcu() for normal and failed-construction teardown
- retain Fixes: 51ab2994c387 as requested
- credit the earlier security-list reporter
[1] https://lore.kernel.org/netdev/20260805102505.740806-1-david.lee@xxxxxxxxxxxxxxx/
[2] https://lore.kernel.org/netdev/CAC_etQFk%3DtGLvbHPmQwOyrYWgRtDru3dSw4T7sZ-9hvVMy_J-g@xxxxxxxxxxxxxx/
Weiming Shi (1):
net/sched: defer qdisc freeing after failed creation
include/net/sch_generic.h | 2 +-
net/sched/sch_api.c | 2 +-
net/sched/sch_generic.c | 20 ++++++++++----------
3 files changed, 12 insertions(+), 12 deletions(-)