Thread (6 messages) 6 messages, 4 authors, 2026-08-11

Re: [PATCH net] gtp: serialize PDP deletion with link teardown

From: Simon Horman <horms@kernel.org>
Date: 2026-08-07 13:13:43
Also in: lkml

On Thu, Aug 06, 2026 at 10:32:26AM +0800, Qing Ming wrote:
PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
network device is being unregistered. The latter is serialized by RTNL,
but the generic-netlink delete path only holds RCU.

Running both paths concurrently can therefore make both paths delete the
same PDP context. On a KASAN-enabled kernel, a reproducer racing DELPDP
against RTM_DELLINK triggered:

  Oops: general protection fault, probably for non-canonical address
  KASAN: maybe wild-memory-access in range 
         [0xdead000000000120-0xdead000000000127]
  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]
  RBP: dead000000000122

The second deletion dereferenced the poisoned hlist pprev pointer.

Take RTNL around the DELPDP lookup and deletion so that PDP creation,
generic-netlink deletion and link teardown use the same serialization
domain.

Fixes: 459aa660eb1d ("gtp: add initial driver for datapath of GPRS Tunneling Protocol (GTP-U)")
Signed-off-by: Qing Ming <redacted>
Hi,

I think it would be good to mention how this problem was found,
and to what extent it has been tested.

You may also want to consider adding an Assisted-by tag as appropriate.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help