Re: [PATCH net v2] net/sched: fix use-after-free in __tcf_action_put()

From: Simon Horman

Date: Sat Oct 10 2026 - 10:52:53 EST


On Thu, Oct 08, 2026 at 06:13:49PM +0000, Jérémy Jean wrote:
> __tcf_action_put() decrements the reference count before decrementing the
> binding count. Another thread can free the action between these operations,
> causing the binding-count update to access freed memory. KASAN reports it
> as:
>
> BUG: KASAN: slab-use-after-free in __tcf_action_put+0x327/0x340
> Write of size 4 at addr ff11000000d46420 by task tc-put-pause/64
>
> Hold the action IDR mutex across both counter updates and IDR removal,
> keeping cleanup outside the lock.
>
> Fixes: 16af6067392c ("net: sched: implement reference counted action release")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@xxxxxxxxxxxxxxxxx>
> ---
>
> Change in v2:
> - Invert the condition of the test.
>
> v1: https://lore.kernel.org/all/20260930211839.620410-2-Jeremy.Jean@xxxxxxxxxxxxxxxxx/

Reviewed-by: Simon Horman <horms@xxxxxxxxxx>