Thread (3 messages) 3 messages, 3 authors, 2025-05-29

Re: [PATCH net v2] net: tipc: fix refcount warning in tipc_aead_encrypt

From: patchwork-bot+netdevbpf@kernel.org
Date: 2025-05-29 10:09:55
Also in: lkml

Hello:

This patch was applied to netdev/net.git (main)
by Paolo Abeni [off-list ref]:

On Tue, 27 May 2025 16:35:44 +0000 you wrote:
syzbot reported a refcount warning [1] caused by calling get_net() on
a network namespace that is being destroyed (refcount=0). This happens
when a TIPC discovery timer fires during network namespace cleanup.

The recently added get_net() call in commit e279024617134 ("net/tipc:
fix slab-use-after-free Read in tipc_aead_encrypt_done") attempts to
hold a reference to the network namespace. However, if the namespace
is already being destroyed, its refcount might be zero, leading to the
use-after-free warning.

[...]
Here is the summary with links:
  - [net,v2] net: tipc: fix refcount warning in tipc_aead_encrypt
    https://git.kernel.org/netdev/net/c/f29ccaa07cf3

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help