Thread (4 messages) flat view 4 messages, 4 authors, 2021-11-21

Re: [syzbot] KASAN: use-after-free Read in rxe_queue_cleanup

From: Zhu Yanjun <zyjzyj2000@gmail.com>
Date: 2021-11-21 14:44:11
Also in: linux-rdma, lkml

On Sun, Nov 21, 2021 at 10:16 PM Leon Romanovsky [off-list ref] wrote:
On Sat, Nov 20, 2021 at 06:02:02PM +0300, Pavel Skripkin wrote:
quoted
On 11/19/21 12:27, syzbot wrote:
quoted
Hello,

syzbot found the following issue on:

HEAD commit:    8d0112ac6fd0 Merge tag 'net-5.16-rc2' of git://git.kernel...
git tree:       net
console output: https://syzkaller.appspot.com/x/log.txt?x=14e3eeaab00000
kernel config:  https://syzkaller.appspot.com/x/.config?x=6d3b8fd1977c1e73
dashboard link: https://syzkaller.appspot.com/bug?extid=aab53008a5adf26abe91
compiler:       gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+aab53008a5adf26abe91@syzkaller.appspotmail.com

Free swap  = 0kB
Total swap = 0kB
2097051 pages RAM
0 pages HighMem/MovableOnly
384517 pages reserved
0 pages cma reserved
==================================================================
BUG: KASAN: use-after-free in rxe_queue_cleanup+0xf4/0x100 drivers/infiniband/sw/rxe/rxe_queue.c:193
Read of size 8 at addr ffff88814a6b6e90 by task syz-executor.3/9534
On error handling path in rxe_qp_from_init() qp->sq.queue is freed and then
rxe_create_qp() will drop last reference to this object. qp clean up
function will try to free this queue one time and it causes UAF bug.

Just for thoughts.
Agree with you. Thanks a lot.

Zhu Yanjun
You are right, can you please submit patch?

Thanks
quoted
diff --git a/drivers/infiniband/sw/rxe/rxe_qp.c
b/drivers/infiniband/sw/rxe/rxe_qp.c
index 975321812c87..54b8711321c1 100644
--- a/drivers/infiniband/sw/rxe/rxe_qp.c
+++ b/drivers/infiniband/sw/rxe/rxe_qp.c
@@ -359,6 +359,7 @@ int rxe_qp_from_init(struct rxe_dev *rxe, struct rxe_qp
*qp, struct rxe_pd *pd,

 err2:
      rxe_queue_cleanup(qp->sq.queue);
+     qp->sq.queue = NULL;
 err1:
      qp->pd = NULL;
      qp->rcq = NULL;





With regards,
Pavel Skripkin
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help