mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] kcm: Fix socket use-after-free in kcm_unattach()
@ 2026-09-17 16:36 Wentao Liang
  2026-09-21 17:24 ` netdev-bot+sashiko
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 16:36 UTC (permalink / raw)
  To: davem
  Cc: edumazet, horms, kuba, linux-kernel, netdev, pabeni, tom,
	Wentao Liang, stable

In the unreserved path of kcm_unattach(), the reference held by the
psock on the underlying TCP socket is dropped with sock_put() before
the socket file is released with fput(csk->sk_socket->file) and before
release_sock() is called at the end of the function. If that was the
last reference on the socket, both uses access freed memory.

Drop the socket reference only after the last use of the socket: move
the fput() before the sock_put() and release the socket lock before
dropping the final reference.

Fixes: ab7ac4eb9832 ("kcm: Kernel Connection Multiplexor module")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 net/kcm/kcmsock.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/kcm/kcmsock.c b/net/kcm/kcmsock.c
index 3912e75079f5..b3838a19f0a7 100644
--- a/net/kcm/kcmsock.c
+++ b/net/kcm/kcmsock.c
@@ -1457,9 +1457,11 @@ static void kcm_unattach(struct kcm_psock *psock)
 		mux->psocks_cnt--;
 		spin_unlock_bh(&mux->lock);
 
-		sock_put(csk);
 		fput(csk->sk_socket->file);
 		kmem_cache_free(kcm_psockp, psock);
+		release_sock(csk);
+		sock_put(csk);
+		return;
 	}
 
 	release_sock(csk);
-- 
2.34.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-21 17:24 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 16:36 [PATCH] kcm: Fix socket use-after-free in kcm_unattach() Wentao Liang
2026-09-21 17:24 ` netdev-bot+sashiko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®