RE: [PATCH] ixgbevf: fix xfrm_state reference leak in ixgbevf_ipsec_rx()

From: Romanowski, Rafal

Date: Tue Oct 06 2026 - 04:14:39 EST


> -----Original Message-----
> From: Simon Horman <horms@xxxxxxxxxx>
> Sent: Monday, September 21, 2026 12:35 PM
> To: Wentao Liang <vulab@xxxxxxxxxxx>
> Cc: andrew+netdev@xxxxxxx; Nguyen, Anthony L <anthony.l.nguyen@xxxxxxxxx>;
> davem@xxxxxxxxxxxxx; edumazet@xxxxxxxxxx; intel-wired-lan@xxxxxxxxxxxxxxxx;
> kuba@xxxxxxxxxx; linux-kernel@xxxxxxxxxxxxxxx; netdev@xxxxxxxxxxxxxxx;
> pabeni@xxxxxxxxxx; Kitszel, Przemyslaw <przemyslaw.kitszel@xxxxxxxxx>;
> sln@xxxxxxxxxxx; stable@xxxxxxxxxxxxxxx
> Subject: Re: [PATCH] ixgbevf: fix xfrm_state reference leak in ixgbevf_ipsec_rx()
>
> On Thu, Sep 17, 2026 at 11:14:18AM +0000, Wentao Liang wrote:
> > ixgbevf_ipsec_find_rx_state() returns the state with an extra
> > reference, which is handed over to the secpath on the success path.
> > When
> > secpath_set() fails, the state has not been stored anywhere yet and
> > the reference is dropped on the floor.
> >
> > Release it before returning.
> >
> > Fixes: 0062e7cc955e0 ("ixgbevf: add VF IPsec offload code")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>
>
> Reviewed-by: Simon Horman <horms@xxxxxxxxxx>

Tested-by: Rafal Romanowski <rafal.romanowski@xxxxxxxxx>