Thread (15 messages) 15 messages, 6 authors, 1d ago

Re: [PATCH bpf v4] bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-07-24 22:10:45
Also in: bpf, lkml

Hello:

This patch was applied to bpf/bpf.git (master)
by Eduard Zingerman [off-list ref]:

On Fri, 24 Jul 2026 18:38:56 +0800 you wrote:
tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
drops and reacquires the socket lock.  Its error path tries to decide
whether msg_tx names the local temporary message by comparing it with
the current value of psock->cork.

This comparison is unsafe when two threads send on the same socket:

[...]
Here is the summary with links:
  - [bpf,v4] bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
    https://git.kernel.org/bpf/bpf/c/2d66a033864e

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help