From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 291E53438A4 for ; Sat, 22 Aug 2026 16:41:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787416869; cv=none; b=qC+QPlyuyLk+on4eXFvO6v6X6ulLKUl2lRSz/2t/kbBQWE+cCPc7FyTmS4vDpLt6CqattOxCDsR0tc+kDCMlhLpFSPbL5CqTKnECXULNM/mVvlDdVCSU41jtxKdPuJpuxkOuCITX4WR2ejKWpwinoXYWnYRxMHiEpcdnRfNM5EE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787416869; c=relaxed/simple; bh=kP1cz0Wgy8H1Vo4OIydwD7cCtpRNRp7He/gqzqKUjIY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uTvIFYNaXeBZ/FG/okjQpKQ2TdEITR6xxWVgsSBuwacoKxib5g07Fy+k1yKttUbArY8Pp7c+b8QvhYUv7Gk80PlIQ11LW3npXbaezTmzBGTXI61/Va8BTNQmql+HWoF440tzcNFYaPdqawa5truseYxwuesJr7TFDT4inzs0xtQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=faXOmRpa; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="faXOmRpa" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38fe113c792so214074a91.3 for ; Sat, 22 Aug 2026 09:41:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787416863; x=1788021663; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=H5sYAzT/WtRiW1Ix2HTkpoXUx65zoV0tVj4oWbHryfc=; b=faXOmRpadohKzUHTIGVP3KXy4KgLAxTUGEBvD3IMZwehSlXZ/UPlHrmFCWrYybWih2 R5v1gpqGxBwTja3lqPfU6in32uG3AFRNrh9cA1s9QJ8l16kUyvMXrNTcmHppcoSbJswv OtcQ1NsrtSufcYRCAvNdcuMhscyK8YAflrTpPcGteNhvBEVGtb9z11iegG0//c1xtmvD OQ57nyh6v7EMopgtS1TuRkWiX3BKnAy//wK0slUE4U2pEPF/dNATvH91xvRZC9PYTk73 +7dlVNVbeVa8f9p2HoPeXtMn55wFty3lq0loZi+0vWih6yUzygTkDTBy/C7OAzXNq9up JtWg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787416863; x=1788021663; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=H5sYAzT/WtRiW1Ix2HTkpoXUx65zoV0tVj4oWbHryfc=; b=BPlVlFGLybnWDCQ9CKWTynA7n44VcQilimpcfChMhjCT8FhTV5j7hfY3EHNxtVIH4T F7Qpt+elXxSbez3GZIY7CxPMGZDT2fm7UZ/HJbDAIUhtfvohlOB0JHpievINLpA+Y6JF pkYCsk3/ufEq2cxYc8nYtwtBHXETb7/M/QrWICfZFwPwrIs0Rdw5QEDqbwWxcGspLTaG r0H9hauoDSHqs+lz/Mr86ErOzniQOZ4ZtKWXZZEyi5lFIOIyoDYKyx+rwhQp2fW4d2Qc GM3KpuneoX+IQj0+o/+kWvuypTbcbbbDw8u57DZPk7AtXaijCTrxWHp4s2UJr58g8efi KQZA== X-Forwarded-Encrypted: i=1; AHgh+RqHIuCmAFt3tMsziXkNN5hfzrrkHzlyLe809ddHU4923fQfkwkjigUILb3eUkh35YcLjiZZpj/uth2Z4JU=@vger.kernel.org X-Gm-Message-State: AFuF++l6kiSmxP3wLTwWdJNRSdP0aYoSl/3AYEdixQIHArI3F9QADcOG aCkZ4YdLEGvodDesl7MHWngae1VZq1Vc99gQ3DQsJR8C6pf1VhvaWuvv X-Gm-Gg: AR+sD10u1QHnnzqFD81ovT68JDx5y+aFFRF/UFWyP45nUBvEqXhC/x8wfD6E0n+bD9Y rbMcvY0dIaKj825lGQ9me9sAyHro3YpHVqCXlJusU1FBv6tbxhWBc+k/ojbI9AHon4Pc4poIWp3 3RgBpOPlXcX+YoAf/AGHgW7P8oKosqSsTlB2P8dxijr3gQb/hAdBSFxT7Iub0Fy2hTgzKgBuWzU j7dN3jc6LZ5ocuPZp03vbMLK9y9sL/Lb9jxJrEhdOVaCct3HjoF/OKRS2SBZqCXAzovm185WLFy jMUFPtSjSRNKr8zGC9/Yo3HgEceFOzwptthEoaiWSoVZoUlUDsdnneyy3SLJNZAa4MhPqv8KgUq 9uEEx8hk+AGrbk9p9kk3zmZst82qoSCfgBY66OD5EwNRB71GSeq577QVMiavdCMKJ56DQjGK0jG kfdjQAPuCSySlpsU3wpoWwfJAzMa7pg64MRJPiwIlI348mwfVMagbCnL0TLI02fogGm26J4ILu6 LdiBqVUMDDUwpBJdfZ+/7mv1llGQykGF6pbF8lV85zOKDnoSSD53Iw= X-Received: by 2002:a17:903:1b65:b0:2d5:3f09:4126 with SMTP id d9443c01a7336-2d64b13195dmr134518165ad.4.1787416863141; Sat, 22 Aug 2026 09:41:03 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f9209fafsm15580796eec.23.2026.08.22.09.40.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 22 Aug 2026 09:41:02 -0700 (PDT) From: Chengfeng Ye To: Jon Maloy , Tung Quang Nguyen , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Tuong Lien , Ying Xue Cc: netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH net] tipc: protect node reset trace dump with node lock Date: Sun, 23 Aug 2026 00:40:55 +0800 Message-ID: <20260822164055.3750284-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The tipc_node_reset_links trace event asks tipc_node_dump() to walk the node's link entries. Unlike the other node events that request link data, this event runs without the node lock. This permits bearer teardown to free a link while the trace callback is dumping it: CPU 0 CPU 1 trace_tipc_node_reset_links() tipc_node_dump() l = n->links[0].link tipc_node_write_lock() kfree(l) n->links[0].link = NULL tipc_node_write_unlock() tipc_link_dump(l) tipc_link_dump() then dereferences the stale pointer. KASAN reported: BUG: KASAN: slab-use-after-free in tipc_link_dump+0x10cb/0x16b0 Read of size 4 by task ksoftirqd/0/14 Call Trace: tipc_link_dump+0x10cb/0x16b0 tipc_node_dump+0x4bb/0x740 trace_event_raw_event_tipc_node_class+0x258/0x360 tipc_node_reset_links+0x14d/0x1a0 tipc_rcv+0x13f5/0x3030 tipc_udp_recv+0x4e3/0x670 Allocated by task 0: tipc_link_create+0x1e1/0x1020 tipc_node_check_dest+0x7d2/0x11a0 tipc_disc_rcv+0xdbf/0x1430 Freed by task 89: kfree+0x131/0x3c0 tipc_node_link_down+0x267/0x4b0 tipc_node_delete_links+0xec/0x160 bearer_disable+0x107/0x260 Take the node read lock around the trace event. This keeps link pointer loads and all dump dereferences serialized against link deletion while preserving the trace contents and reset flow. Fixes: eb18a510b5cd ("tipc: add trace_events for tipc node") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/tipc/node.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/tipc/node.c b/net/tipc/node.c index 683a136e53ef..127848e8a644 100644 --- a/net/tipc/node.c +++ b/net/tipc/node.c @@ -1333,7 +1333,9 @@ static void tipc_node_reset_links(struct tipc_node *n) pr_warn("Resetting all links to %x\n", n->addr); + tipc_node_read_lock(n); trace_tipc_node_reset_links(n, true, " "); + tipc_node_read_unlock(n); for (i = 0; i < MAX_BEARERS; i++) { tipc_node_link_down(n, i, false); } -- 2.43.0