[PATCH] ipconfig: fix use-after-free of device list after ic_close_devs()

From: Henry Martin

Date: Fri Oct 09 2026 - 03:45:50 EST


ic_close_devs() kfree()s every ic_device node but leaves the static
ic_first_dev and ic_dev pointers dangling behind. When a DHCP reply
consists of an OFFER that is never followed by an ACK (a misbehaving
or lossy DHCP server, or a network that drops the ACK), the boot-time
autoconfiguration loop becomes vulnerable:

1. ic_bootp_recv() accepts the OFFER and records ic_dev = <list
node> ("We have a winner!" state);
2. the retransmit round times out in ic_dynamic(), so
ic_close_devs() frees the whole list — node included;
3. the dynamic retry path (try_try_again) runs ic_open_devs() and
ic_dynamic() again; on failure it falls through ic_close_devs()
once more, where the entry point evaluates

struct net_device *selected_dev = ic_dev ? ic_dev->dev : NULL;

— an 8-byte use-after-free read against the freed ic_device.

KASAN confirms (boot-time bootload, no userspace yet):

BUG: KASAN: slab-use-after-free in ic_close_devs+0x214/0x220
Read of size 8 by task swapper/0/1
Call Trace:
ic_close_devs+0x214/0x220
ip_auto_config+0x172b/0x34e0
do_one_initcall+0x9f/0x370
kernel_init_freeable+0x432/0x760
kernel_init+0x24/0x1f0
Allocated by task 1:
__kmalloc_cache_noprof+0x1b5/0x430 <- ip_auto_config+0x587/0x34e0
(ic_open_devs' kmalloc_obj of the ic_device list node)
Freed by task 1:
kfree+0x166/0x450 <- ic_close_devs+0xcb/0x220
(ic_close_devs freeing the same node at round end)

NULL both pointers after the free loop so subsequent retry rounds
take the clean empty-list path instead of acting on freed entries.

This vulnerability was discovered by Tencent CodeBuddy Security.

Cc: stable@xxxxxxxxxxxxxxx
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
---
net/ipv4/ipconfig.c | 7 +++++++
1 file changed, 7 insertions(+)

diff --git a/net/ipv4/ipconfig.c b/net/ipv4/ipconfig.c
index 1b8585404a41..ac4851e59c3b 100644
--- a/net/ipv4/ipconfig.c
+++ b/net/ipv4/ipconfig.c
@@ -346,6 +346,13 @@ static void __init ic_close_devs(void)
kfree(d);
}
rtnl_unlock();
+
+ /* The whole ic_device list was just kfree()'d above; clear the
+ * static pointers so retry rounds (e.g. dynamic retry after an
+ * OFFER without ACK) don't dereference them (use-after-free).
+ */
+ ic_first_dev = NULL;
+ ic_dev = NULL;
}

/*
--
2.43.7