[PATCH net v2] ipconfig: fix use-after-free of device list after ic_close_devs()

From: Henry Martin

Date: Sat Oct 10 2026 - 04:50:37 EST


ic_close_devs() kfree()s every ic_device node but leaves the static
ic_first_dev and ic_dev pointers dangling behind. When a DHCP
negotiation gets an OFFER but never the matching ACK, ic_bootp_recv()
accepts the OFFER and records ic_dev = <list node>, the round times
out and ic_close_devs() frees the whole list — node included. The
next failed retry round runs ic_close_devs() once more, evaluating

selected_dev = ic_dev ? ic_dev->dev : NULL;

against the freed ic_device — an 8-byte use-after-free read.

KASAN confirms:

BUG: KASAN: slab-use-after-free in ic_close_devs+0x214/0x220
Read of size 8
ic_close_devs <- ip_auto_config
Allocated by: ip_auto_config (ic_open_devs)
Freed by: ic_close_devs <- ip_auto_config

NULL both pointers after the free loop so retry rounds take the
clean empty-list path.

This memory-safety issue was discovered by Tencent CodeBuddy Security.

Cc: stable@xxxxxxxxxxxxxxx
Fixes: 46acf7bdbc72 ("Revert "net: ipv4: handle DSA enabled master network devices"")
Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
---
Changes in v2:
- Fixes: tag corrected to the commit that introduced the ic_dev->dev
dereference that makes this a UAF (46acf7bdbc72); in 2.6.12 ic_dev
was a struct net_device * that was only compared, never dereferenced.
- Code comment in ic_close_devs() dropped per review.
- Message reduced to the memory-safety mechanism (no vulnerability
framing).

net/ipv4/ipconfig.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/net/ipv4/ipconfig.c b/net/ipv4/ipconfig.c
index 1b8585404a41..ac4851e59c3b 100644
--- a/net/ipv4/ipconfig.c
+++ b/net/ipv4/ipconfig.c
@@ -346,6 +346,9 @@ static void __init ic_close_devs(void)
kfree(d);
}
rtnl_unlock();
+
+ ic_first_dev = NULL;
+ ic_dev = NULL;
}

/*
--
2.43.7