From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f171.google.com (mail-qt1-f171.google.com [209.85.160.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7879D374170 for ; Sun, 14 Jun 2026 13:04:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781442295; cv=none; b=dOHBTv6KFFEuT2JEBxwwOtgh52DL4YN9KgJwmLiAc8+EScngo08DIcTBroivlsCanIEEkZ8w1It2CNqKBSQ9P5E0J6LF+lKme0jQAbAI8A5ai+R0NsGRSwppDftHd75kT/ituLEHFHI82iATTKriMvKIdofYUlRDP0EqbvQpufs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781442295; c=relaxed/simple; bh=ADCNFUh94Rv4KNKJvYbbe8p47vvd4whs5tudmJRWnb8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CkW82O3nYNtA7BXhjA25YjIWR8NEZk1C0d0zjsEoAErVWsYISEFfRS5Q0/LGLuQwjO4GD+3kbDgDq01lNucLo4WAcV07UMMAqx66bDKhWCJNKGCa/14ATWHBEo4lKOZ6KVuDRo0BSBKQGDGq3/OgGWwFeT31c0OLsx2W0Inchnk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=APtjPMMJ; arc=none smtp.client-ip=209.85.160.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="APtjPMMJ" Received: by mail-qt1-f171.google.com with SMTP id d75a77b69052e-517b1f2c668so27766381cf.2 for ; Sun, 14 Jun 2026 06:04:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781442293; x=1782047093; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=6GPmxYA8Yy2PWTqYiGecskY9yfd7+d/20uBDlyc5AuA=; b=APtjPMMJr7psP9tQyrGlwR1AqtdHU4ElC4d1EJ0WpJ6QfGFQNwskHSVyW3oqXiGQq9 e+JhC3zwee1uPvy3qSA15Qu5KJCoIlciXKwr2Q+W7LfkRmb7Ecg4HmivVMvWVtrE+5wW 0Vz3rLi05eFaQnv9SrrBul9WjSRvWRwtxKA1T7vmwb3trIMDiLt0hGW46vFcLSUk68wV TngkOQpWz3s4A3tmh5Kb8IYqZH1y/scDOSOr1KIbv0Y0ayaqWEirG31dH4j9SxI9B8Ps kiwsCORessnXzjdIYd3oPF4hc6Wbpp+EJu9L+J6CY0aHobzx0kTs7+0NOXbrWbPQliBr frnA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781442293; x=1782047093; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=6GPmxYA8Yy2PWTqYiGecskY9yfd7+d/20uBDlyc5AuA=; b=ih0bMTqYtcDUumEBQgLOuyLd9bkkds2C/HqxSZcvnaNQ2YHcezxkvUKAKdRDpAtJkY HtKupicxT/qEfSLnkS05ZSH6MO0BfHSeKQ4T727aF3I2950rWSD+clnJ5H6i1zaDlWRy 31obMiN6BnifUo0e2GhHgs08xY1lLNKFwWOuB4ymM5Ey8iw4rNREYKUqAOaJyNi3VS7B gx0ysOz3eHmNwqzv5//H1+v2SGY5wBogMoct+SQE85dH9TE48sd64wmbidkDc0wx3XAI Tq/2XJNnqsEuOLDhDLkqNbDIO8rvYNis+piGw9iuHBJfD3Oxo+JzAdSVToktNNNg5SzL zGvQ== X-Forwarded-Encrypted: i=1; AFNElJ8icSkvnj/PYLy5Up12qitQ1akoypfxxe2+8cK8w7Nf1oIhBBSX7gQUlpbi7trSBKnzFZZtJl7NFQPT3Co=@vger.kernel.org X-Gm-Message-State: AOJu0YzG5qpbZYnpyhxUSJdWY775g7nvr+P+TYJbElwH5AiIQ4EEvPlh BntbBoenznCqVVMW4mkOA2CKkUBp6TvrtD3LsO8oTO42Wv7l0uz5ZNuj X-Gm-Gg: Acq92OE/0Rfv6lZKj2+bFq4EOC15p0UJqthpNIJm+k+ofWwzhiBR0jAPxBU0mnDH3BW 9/qeDVZ+RqFz5gESJBizk1BYMyvQl4MHmcvG+L31atcpLfpekwhVtukB6/Oy5q3iuQ3oh9TBszn m8EbURTD7kkrPvv18tqScGPj2H3369dP6K7NWQbkGxB5B63zCVnxl+wmDqT094J2zKWa+I7bn2B Z0RwDGhOD8VoopxD19xblyVon5Om25qCitFy5H631ixgjEidqbHI9eyeL7YolxpqeHRvZ8YloKf u0Kjz/b0QrKTxQDnVXCzTJJtplmKSo+e6lNuLv2nOUwlwgw5GQJcJQzjVZ2m4ma4hAA7g+aUwBa Q4Vh7tn0ZeEUhz55lmzUWkbEZTYZBsWIeKRM7yA74rqFywBqfKGwgJmeKn+DqXdmj5H9zfvDd1y kKwYPeoN2AwGcDBdBIpfZT0LPySpBPp7pQF99zJ4zaIi/qSrnLVrj3Fn4AHhGAG7vKKt2udIdBd DubiwcGmR8CZ5RX9hxvh92AUBCmRue2hjIlSXl20JY= X-Received: by 2002:a05:622a:a0f:b0:517:9593:edaa with SMTP id d75a77b69052e-517fe4d7868mr162415471cf.31.1781442293315; Sun, 14 Jun 2026 06:04:53 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-517fb854290sm73644611cf.31.2026.06.14.06.04.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 14 Jun 2026 06:04:52 -0700 (PDT) From: Michael Bommarito To: Zhu Yanjun , Jason Gunthorpe , Leon Romanovsky Cc: Bob Pearson , linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] RDMA/rxe: destroy the mcg when rxe_mcast_add() fails in rxe_get_mcg() Date: Sun, 14 Jun 2026 09:04:43 -0400 Message-ID: <20260614130443.2517578-1-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit rxe_get_mcg() inserts the new mcg into rxe->mcg_tree and takes the tree reference before calling rxe_mcast_add() outside mcg_lock. On failure the error path frees the mcg with a bare kfree() without erasing the tree node or dropping the tree reference, so the freed mcg stays linked in mcg_tree and the next __rxe_lookup_mcg() on the same mgid uses it after free. rxe_mcast_add() fails reachably from an unprivileged caller: -ENODEV when the backing netdev is removed, or a propagated dev_mc_add() error. Tear the mcg down with __rxe_destroy_mcg() on the failure path, as rxe_attach_mcast() already does. Reproduced under KASAN on QEMU by forcing the rxe_mcast_add() failure; the use-after-free in __rxe_lookup_mcg() is gone after this change. Fixes: a926a903b7dc ("RDMA/rxe: Do not call dev_mc_add/del() under a spinlock") Cc: stable@vger.kernel.org # v5.18+ Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito --- Reproduction (v7.1-rc4, x86_64 QEMU/KVM, KASAN, Soft-RoCE): Forcing rxe_mcast_add() to return -ENODEV, an unprivileged ATTACH_MCAST on a UD QP leaves the freed mcg linked in mcg_tree. On the stock kernel the next lookup reports BUG: KASAN: slab-use-after-free in __rxe_lookup_mcg and the subsequent rb_erase() panics. Patched, the forced failure returns cleanly. Control: with injection disabled, re-attach and detach of the same MGID and a two-QP join/leave are KASAN-clean on both trees. tools/testing/selftests/rdma has no rxe_mcast coverage; harness off-list on request. drivers/infiniband/sw/rxe/rxe_mcast.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/drivers/infiniband/sw/rxe/rxe_mcast.c b/drivers/infiniband/sw/rxe/rxe_mcast.c index 5cad720..7f148d4 100644 --- a/drivers/infiniband/sw/rxe/rxe_mcast.c +++ b/drivers/infiniband/sw/rxe/rxe_mcast.c @@ -196,6 +196,8 @@ static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid, __rxe_insert_mcg(mcg); } +static void __rxe_destroy_mcg(struct rxe_mcg *mcg); + /** * rxe_get_mcg - lookup or allocate a mcg * @rxe: rxe device object @@ -247,7 +249,13 @@ static struct rxe_mcg *rxe_get_mcg(struct rxe_dev *rxe, union ib_gid *mgid) if (!err) return mcg; - kfree(mcg); + /* mcg was made visible in mcg_tree; unwind the insert before freeing. */ + spin_lock_bh(&rxe->mcg_lock); + __rxe_destroy_mcg(mcg); + spin_unlock_bh(&rxe->mcg_lock); + kref_put(&mcg->ref_cnt, rxe_cleanup_mcg); + return ERR_PTR(err); + err_dec: atomic_dec(&rxe->mcg_num); return ERR_PTR(err); base-commit: 5200f5f493f79f14bbdc349e402a40dfb32f23c8 -- 2.53.0