[PATCH] 9p: pin request under client lock in p9_tag_lookup

From: Jérémy Jean

Date: Wed Sep 30 2026 - 17:26:08 EST


9P clients keep separate request tables but share one request cache.
p9_tag_lookup() can race with the final p9_req_put() and pin a request
reused by another client. Both clients can then complete it, freeing
its response while the caller still parses it, creating a UAF that
KASAN reports as:

BUG: KASAN: slab-use-after-free in p9pdu_readf+0x362/0x2130
Read of size 4 at addr ffff888009520000 by task repro/82

Freed by task 50:
p9_req_put+0x1a4/0x1f0
p9_read_work+0x916/0xf80

Hold the client lock while finding and pinning the request, preventing
removal and reuse between these operations.

Fixes: 728356dedeff ("9p: Add refcount to p9_req_t")
Cc: stable@xxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Jérémy Jean <Jeremy.Jean@xxxxxxxxxxxxxxxxx>
---
net/9p/client.c | 26 ++++++++++----------------
1 file changed, 10 insertions(+), 16 deletions(-)

diff --git a/net/9p/client.c b/net/9p/client.c
index ef64546c6d52..fd72f05128d1 100644
--- a/net/9p/client.c
+++ b/net/9p/client.c
@@ -235,24 +235,18 @@ p9_tag_alloc(struct p9_client *c, int8_t type, uint t_size, uint r_size,
struct p9_req_t *p9_tag_lookup(struct p9_client *c, u16 tag)
{
struct p9_req_t *req;
+ unsigned long flags;

- rcu_read_lock();
-again:
+ /*
+ * Pin the request while removal from this client's IDR is excluded.
+ * Tag equality alone cannot distinguish a request recycled for another
+ * client from the same SLAB_TYPESAFE_BY_RCU cache.
+ */
+ spin_lock_irqsave(&c->lock, flags);
req = idr_find(&c->reqs, tag);
- if (req) {
- /* We have to be careful with the req found under rcu_read_lock
- * Thanks to SLAB_TYPESAFE_BY_RCU we can safely try to get the
- * ref again without corrupting other data, then check again
- * that the tag matches once we have the ref
- */
- if (!p9_req_try_get(req))
- goto again;
- if (req->tc.tag != tag) {
- p9_req_put(c, req);
- goto again;
- }
- }
- rcu_read_unlock();
+ if (req && !p9_req_try_get(req))
+ req = NULL;
+ spin_unlock_irqrestore(&c->lock, flags);

return req;
}
--
2.47.3