RE: [PATCH v2 2/2] tipc: fix use-after-free in netns teardown
From: Tung Quang Nguyen
Date: Sun Oct 04 2026 - 21:47:15 EST
>Subject: [PATCH v2 2/2] tipc: fix use-after-free in netns teardown
>
>conn_put() decreases the reference count of a connection, and when it
>reaches zero, tipc_conn_kref_release() removes the connection from conn_idr
>and frees it. Removing the entry is protected by idr_lock, but decreasing the
>count is not.
>
>During netns dismantle, it may happen that a connection gets its count
>dropped to zero by conn_put() while tipc_topsrv_stop() still holds the lock
>idr_lock. tipc_topsrv_stop() calls conn_get() on that connection whose count is
>already zero, and then releases idr_lock.
>tipc_conn_kref_release() can then free the connection before
>tipc_conn_close() uses it. KASAN reports a UAF as:
>
> BUG: KASAN: slab-use-after-free in tipc_conn_close (net/tipc/topsrv.c:158)
> Read of size 8 at addr ff1100000cf4f408 by task kworker/u16:3/70
>
>Stop accepting connections before walking conn_idr. Use
>kref_get_unless_zero() to avoid taking references when the count is zero.
>Walk forward through conn_idr to disconnect all connections before draining
>the workqueues.
This does not fix the root cause.
I fixed the issue in this patch: https://git.kernel.org/netdev/net/c/3acdd44385bc
Please update your net tree to check out the fix.
--
pw-bot: rejected