* [PATCH 7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp()
@ 2026-09-16 18:44 Wentao Liang
2026-09-23 8:35 ` Leon Romanovsky
0 siblings, 1 reply; 3+ messages in thread
From: Wentao Liang @ 2026-09-16 18:44 UTC (permalink / raw)
To: bernard.metzler; +Cc: jgg, leon, linux-kernel, linux-rdma, Wentao Liang, stable
The reference taken by siw_qp_id2obj() is dropped before the address
of the embedded ib_qp is taken from the QP. If that reference was
the last one the QP is freed and the pointer returned to the iwarp
core is dangling; the core only pins the QP with iw_add_ref() after
the call has returned.
Copy the pointer while the reference is still held.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/infiniband/sw/siw/siw_main.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_main.c b/drivers/infiniband/sw/siw/siw_main.c
index 9735b75ac933..c08796e4262a 100644
--- a/drivers/infiniband/sw/siw/siw_main.c
+++ b/drivers/infiniband/sw/siw/siw_main.c
@@ -217,8 +217,11 @@ static struct ib_qp *siw_get_base_qp(struct ib_device *base_dev, int id)
/*
* siw_qp_id2obj() increments object reference count
*/
+ struct ib_qp *base_qp = &qp->base_qp;
+
siw_qp_put(qp);
- return &qp->base_qp;
+
+ return base_qp;
}
return NULL;
}
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp()
2026-09-16 18:44 [PATCH 7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp() Wentao Liang
@ 2026-09-23 8:35 ` Leon Romanovsky
2026-09-23 11:37 ` Bernard Metzler
0 siblings, 1 reply; 3+ messages in thread
From: Leon Romanovsky @ 2026-09-23 8:35 UTC (permalink / raw)
To: bernard.metzler, Wentao Liang; +Cc: jgg, linux-kernel, linux-rdma, stable
On Wed, 16 Sep 2026 18:44:00 +0000, Wentao Liang wrote:
> The reference taken by siw_qp_id2obj() is dropped before the address
> of the embedded ib_qp is taken from the QP. If that reference was
> the last one the QP is freed and the pointer returned to the iwarp
> core is dangling; the core only pins the QP with iw_add_ref() after
> the call has returned.
>
> Copy the pointer while the reference is still held.
>
> [...]
Applied, thanks!
[7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp()
https://git.kernel.org/rdma/rdma/c/ef15197f81ffed
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp()
2026-09-23 8:35 ` Leon Romanovsky
@ 2026-09-23 11:37 ` Bernard Metzler
0 siblings, 0 replies; 3+ messages in thread
From: Bernard Metzler @ 2026-09-23 11:37 UTC (permalink / raw)
To: Leon Romanovsky, Wentao Liang; +Cc: jgg, linux-kernel, linux-rdma, stable
On 23.09.2026 10:35, Leon Romanovsky wrote:
>
> On Wed, 16 Sep 2026 18:44:00 +0000, Wentao Liang wrote:
>> The reference taken by siw_qp_id2obj() is dropped before the address
>> of the embedded ib_qp is taken from the QP. If that reference was
>> the last one the QP is freed and the pointer returned to the iwarp
>> core is dangling; the core only pins the QP with iw_add_ref() after
>> the call has returned.
>>
>> Copy the pointer while the reference is still held.
>>
>> [...]
>
> Applied, thanks!
>
> [7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp()
> https://git.kernel.org/rdma/rdma/c/ef15197f81ffed
>
> Best regards,
excellent, thanks.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-23 11:37 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-16 18:44 [PATCH 7/7] RDMA/siw: Fix qp use-after-free in siw_get_base_qp() Wentao Liang
2026-09-23 8:35 ` Leon Romanovsky
2026-09-23 11:37 ` Bernard Metzler
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®