RE: [PATCH net] tipc: protect received keys from concurrent flush

From: Tung Quang Nguyen

Date: Fri Oct 02 2026 - 08:12:12 EST


>Subject: [PATCH net] tipc: protect received keys from concurrent flush
>
>tipc_crypto_key_synch() can queue the RX worker again while it is still using rx-
>>skey. If tipc_crypto_key_flush() cancels that queued work, it frees the key
>without waiting for the running worker. The worker can then read freed
>memory or free the key a second time. Racing key exchange with key flush
>triggers KASAN:
>
> [ 12.986077] BUG: KASAN: double-free in
>tipc_crypto_key_flush+0x401/0x530
> [ 12.987937] Free of addr ff11000002268080 by task peer/112
> ...
> [ 12.991938] kfree+0x163/0x430
> ...
> [ 12.991983] tipc_crypto_key_flush+0x401/0x530
> ...
> [ 12.992152] tipc_nl_node_flush_key+0x174/0x210
>
Please update your changelog with decoded stack trace.
Do you have a reproducer ?