Re: [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device
From: Cen Zhang
Date: Fri Oct 09 2026 - 04:22:26 EST
Hi Eric,
Eric Dumazet <edumazet@xxxxxxxxxx> 于2026年10月9日周五 14:54写道:
>
> This is very confusing.
> The changelog shows only the KASAN splat, which is really not that
> interesting here.
> The refcount_t: addition on 0 warning that must precede it would be
> stronger evidence, as in the IPv6 commit.
>
> So this looks like a modified kernel or something like AI hallucination ?
> Please elaborate
>
> pw-bot: cr
To Answer the robot's questions. I found this issue through
AI-assisted code analysis,
then built a test case to actually triggered it. I were not aware
of Baul's earlier submission at that point. The triggering run first reported:
------------[ cut here ]------------
refcount_t: addition on 0; use-after-free.
WARNING: lib/refcount.c:25 at refcount_warn_saturate+0xea/0x110,
CPU#1: ip_core_fixture/498
CPU: 1 UID: 0 PID: 498 Comm: ip_core_fixture Not tainted
7.2.0-rc5-pmb-bt-functional-v1+ #1 PREEMPT(lazy)
RIP: 0010:refcount_warn_saturate+0xea/0x110
Call Trace:
<TASK>
inet_netconf_get_devconf+0xcbc/0xe40
? __pfx_inet_netconf_get_devconf+0x10/0x10
rtnetlink_rcv_msg+0x7b9/0xce0
[...]
Best regards,
Cen Zhang