Thread (4 messages) flat view 4 messages, 2 authors, 2017-09-13

Re: [patch net] net: sched: fix use-after-free in tcf_action_destroy and tcf_del_walker

From: David Miller <davem@davemloft.net>
Date: 2017-09-13 20:59:49

From: Jiri Pirko <jiri@resnulli.us>
Date: Wed, 13 Sep 2017 22:50:06 +0200
Wed, Sep 13, 2017 at 06:34:28PM CEST, davem@davemloft.net wrote:
quoted
From: Jiri Pirko <jiri@resnulli.us>
Date: Wed, 13 Sep 2017 17:32:37 +0200
quoted
From: Jiri Pirko <redacted>

Recent commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu") removed
freeing in call_rcu, which changed already existing hard-to-hit
race condition into 100% hit:

[  598.599825] BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
[  598.607782] IP: tcf_action_destroy+0xc0/0x140

Or:

[   40.858924] BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
[   40.862840] IP: tcf_generic_walker+0x534/0x820

Fix this by storing the ops and use them directly for module_put call.

Fixes: a85a970af265 ("net_sched: move tc_action into tcf_common")
Signed-off-by: Jiri Pirko <redacted>
Applied, thanks Jiri.
Oh, I forgot to mention, this would be nice to push to stable.
Ok, queued up.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help