Thread (9 messages) 9 messages, 2 authors, 2d ago

RE: [PATCH net v8 2/3] tipc: fix NULL deref in deferred bulk distribution on publish failure

From: Tung Quang Nguyen <hidden>
Date: 2026-07-20 15:44:23
Also in: lkml

Subject: [PATCH net v8 2/3] tipc: fix NULL deref in deferred bulk distribution on
publish failure

tipc_net_finalize() does not check the return value of tipc_nametbl_publish().
If the publish fails, for example on a GFP_ATOMIC allocation failure, the node
state name never lands in cluster_scope, but tn->finalized is still set. A worker
deferred by
tipc_named_node_up() then wakes and calls named_distribute() with an
empty list. That replays the same unguarded buf_msg(skb_peek_tail(list)) tail
stamp, this time on the tipc_node_dist_bulk workqueue:

KASAN: null-ptr-deref in range [0x00000000000000c8-0x00000000000000cf]
RIP: 0010:named_distribute (net/tipc/name_distr.c:200)
Workqueue: events tipc_node_dist_bulk
Call Trace:
 tipc_named_dist_cluster_scope (net/tipc/name_distr.c:267)
 tipc_node_dist_bulk (net/tipc/node.c:403)
 process_one_work
 worker_thread
Kernel panic - not syncing: Fatal exception in interrupt

Check the publish result and warn on failure, but still set finalized, otherwise
deferred workers would sleep forever. In
tipc_named_dist_cluster_scope() re-check cluster_scope after the wait and
skip the distribution when it is empty. This is a permanent condition, so return
0 instead of an error, otherwise the link would be bounced forever. Also guard
the tail stamp in named_distribute() itself, so a caller that misses the
precondition gets a warning and a link reset through the existing -ENOBUFS
path instead of a crash.

Reproducing this needs an allocation failure during finalize, so I verified it by
stubbing out the publish call: both nodes log the failure, the workers skip the
distribution, no crash, no link flap.
The normal path is unchanged with the same two-node test.

Fixes: cad2929dc432 ("tipc: update a binding service via broadcast")
Reported-by: Xiang Mei <redacted>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Weiming Shi <redacted>
Please drop this patch because sashiko reports the same issue for patch 1/3: https://sashiko.dev/#/patchset/20260718092544.785289-1-bestswngs%40gmail.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help