Thread (10 messages) 10 messages, 5 authors, 2026-03-25

Re: [PATCH net v2] virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false

From: Jakub Kicinski <kuba@kernel.org>
Date: 2026-03-15 01:12:44
Also in: lkml, stable, virtualization

On Sat, 14 Mar 2026 21:11:33 +0100 Eric Dumazet wrote:
quoted
On Thu, 12 Mar 2026 10:54:06 +0800 xietangxin wrote:  
quoted
Fixes: f2fc6a54585a ("[NETNS][IPV6] route6 - move ip6_dst_ops inside the network namespace")
Cc: stable@vger.kernel.org
Signed-off-by: xietangxin <redacted>  
The Fixes tag should be:

Fixes: 0287587884b1 ("net: better IFF_XMIT_DST_RELEASE support")  
I disagree

What was the situation before this patch ?
My thinking process was that it's fairly unusual that the dst is kept
because the stack decided so. Normally its the device driver that asks
for dst to be kept when its xmit is called. I thought 0287587884b1 was
the first time when stack could make the dst decision behind device
driver's back. But my analysis was very shallow, could well be wrong.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help