On 2026-09-23 08:17:16, Mahanta Jambigi wrote:
The diag dump walks the socket hash table under a read_lock and dereferences
conn->lgr and conn->lnk. Two terminal teardown paths drop those references via
smc_conn_free() while the socket is still hashed:
- smc_conn_kill() -> smc_close_active_abort() -> smc_conn_free()
- smc_close_passive_work() -> smc_conn_free()
This allows the diag reader to dereference a freed lgr or lnk.
Fix it by unhashing the socket before smc_conn_free() is called at the two
terminal teardown sites in smc_close.c.
Additionally, smc_conn_abort() calls smc_conn_free() during early handshake
aborts while the socket remains hashed in SMC_INIT state. The
smc_listen_out_err() path leaves the socket hashed in SMC_CLOSED state after
smc_conn_abort() returns. Guard the conn/lgr/lnk inspection blocks in
__smc_diag_dump() by skipping them when the socket is in SMC_INIT or SMC_CLOSED
state.
Fixes: f16a7dd5cf27 ("smc: netlink interface for SMC sockets")
Fixes: 9dbe086c69b8 ("net/smc: fix invalid link access in dumping SMC-R connections")
Signed-off-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Best regards,
Dust