* [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device
@ 2026-10-09 6:21 Cen Zhang
2026-10-09 6:54 ` Eric Dumazet
0 siblings, 1 reply; 3+ messages in thread
From: Cen Zhang @ 2026-10-09 6:21 UTC (permalink / raw)
To: dsahern, idosch, davem, edumazet, kuba, pabeni, horms, jiri
Cc: netdev, linux-kernel, baul.lee, baijiaju1990, jjzuming, zzzccc427
in_dev_get() samples dev->ip_ptr under RCU and unconditionally
increments the in_device reference count. Device teardown can clear
the pointer and drop the last reference after the sample but before
the increment. RCU keeps the allocation accessible during the lookup,
but does not guarantee that a reference can still be acquired.
Commit 9d40c84cf5bc ("net: devinet: Reduce refcount before grace period")
moved the final put before the grace period. A zero-count increment now
warns and saturates the count, but cannot cancel the RCU free that has
already been queued. Returning that pointer lets callers access the
allocation after leaving RCU, when it can have been freed.
Use refcount_inc_not_zero() and return NULL if the reference cannot be
acquired, following the in6_dev_get() fix in commit 0e243671bc7b ("ipv6:
prevent in6_dev_get() from resurrecting inet6_dev"). A successful
increment retains the object for the caller. Under RTNL, a published
in_device still has a live reference, so reference acquisition is
unchanged. Callers already account for a NULL dev->ip_ptr result.
The RTM_GETNETCONF handler already checks for NULL and can keep
RTNL_FLAG_DOIT_UNLOCKED. This fixes reference acquisition in the helper
rather than serializing that one reader with teardown.
KASAN report as below:
BUG: KASAN: slab-use-after-free in inet_netconf_fill_devconf+0x748/0x790
Read of size 4 at addr ffff88811d70b958 by task ip_core_fixture/498
Call Trace:
[...]
inet_netconf_fill_devconf+0x748/0x790
inet_netconf_get_devconf+0x41c/0xe40
rtnetlink_rcv_msg+0x7b9/0xce0
netlink_rcv_skb+0x133/0x390
[...]
Allocated by task 496:
[...]
inetdev_init+0x60/0x550
inetdev_event+0x71e/0x1780
[...]
Freed by task 0:
[...]
kfree+0x12b/0x530
in_dev_free_rcu+0x51/0x90
rcu_core+0x661/0x1d10
[...]
Last potentially related work creation:
[...]
__call_rcu_common.constprop.0+0x76/0xbd0
in_dev_finish_destroy+0x12e/0x190
inetdev_event+0xa37/0x1780
[...]
Fixes: 9d40c84cf5bc ("net: devinet: Reduce refcount before grace period")
Reported-by: Baul Lee <baul.lee@xbow.com>
Closes: https://lore.kernel.org/netdev/20260815172032.79740-1-baul.lee@xbow.com/
Assisted-by: LLM
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
---
Changes in v2:
- Replace the RTNL workaround with non-zero reference acquisition.
- Keep RTM_GETNETCONF unlocked and return NULL for a retired in_device.
- Correct Fixes to 9d40c84cf5bc, as requested in the earlier review.
- Trim the traces and avoid unsupported double-destruction claims.
Link to v1: https://lore.kernel.org/r/pm-ip-core-objects-candidate-0002-v3-4af089192b0b62b40b9c@gmail.com
include/linux/inetdevice.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/inetdevice.h b/include/linux/inetdevice.h
index 6032eea2539a..a1446da64200 100644
--- a/include/linux/inetdevice.h
+++ b/include/linux/inetdevice.h
@@ -245,8 +245,8 @@ static inline struct in_device *in_dev_get(const struct net_device *dev)
rcu_read_lock();
in_dev = __in_dev_get_rcu(dev);
- if (in_dev)
- refcount_inc(&in_dev->refcnt);
+ if (in_dev && !refcount_inc_not_zero(&in_dev->refcnt))
+ in_dev = NULL;
rcu_read_unlock();
return in_dev;
}
base-commit: 6d25ffca055a77787c21a36b66c253f76239411b
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device
2026-10-09 6:21 [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device Cen Zhang
@ 2026-10-09 6:54 ` Eric Dumazet
2026-10-09 8:16 ` Cen Zhang
0 siblings, 1 reply; 3+ messages in thread
From: Eric Dumazet @ 2026-10-09 6:54 UTC (permalink / raw)
To: Cen Zhang
Cc: dsahern, idosch, davem, kuba, pabeni, horms, jiri, netdev,
linux-kernel, baul.lee, baijiaju1990, jjzuming
Le ven. 9 oct. 2026 à 08:21, Cen Zhang <zzzccc427@gmail.com> a écrit :
>
> in_dev_get() samples dev->ip_ptr under RCU and unconditionally
> increments the in_device reference count. Device teardown can clear
> the pointer and drop the last reference after the sample but before
> the increment. RCU keeps the allocation accessible during the lookup,
> but does not guarantee that a reference can still be acquired.
>
> Commit 9d40c84cf5bc ("net: devinet: Reduce refcount before grace period")
> moved the final put before the grace period. A zero-count increment now
> warns and saturates the count, but cannot cancel the RCU free that has
> already been queued. Returning that pointer lets callers access the
> allocation after leaving RCU, when it can have been freed.
>
> Use refcount_inc_not_zero() and return NULL if the reference cannot be
> acquired, following the in6_dev_get() fix in commit 0e243671bc7b ("ipv6:
> prevent in6_dev_get() from resurrecting inet6_dev"). A successful
> increment retains the object for the caller. Under RTNL, a published
> in_device still has a live reference, so reference acquisition is
> unchanged. Callers already account for a NULL dev->ip_ptr result.
>
> The RTM_GETNETCONF handler already checks for NULL and can keep
> RTNL_FLAG_DOIT_UNLOCKED. This fixes reference acquisition in the helper
> rather than serializing that one reader with teardown.
>
> KASAN report as below:
>
> BUG: KASAN: slab-use-after-free in inet_netconf_fill_devconf+0x748/0x790
> Read of size 4 at addr ffff88811d70b958 by task ip_core_fixture/498
>
> Call Trace:
> [...]
> inet_netconf_fill_devconf+0x748/0x790
> inet_netconf_get_devconf+0x41c/0xe40
> rtnetlink_rcv_msg+0x7b9/0xce0
> netlink_rcv_skb+0x133/0x390
> [...]
>
> Allocated by task 496:
> [...]
> inetdev_init+0x60/0x550
> inetdev_event+0x71e/0x1780
> [...]
>
> Freed by task 0:
> [...]
> kfree+0x12b/0x530
> in_dev_free_rcu+0x51/0x90
> rcu_core+0x661/0x1d10
> [...]
>
> Last potentially related work creation:
> [...]
> __call_rcu_common.constprop.0+0x76/0xbd0
> in_dev_finish_destroy+0x12e/0x190
> inetdev_event+0xa37/0x1780
> [...]
This is very confusing.
The changelog shows only the KASAN splat, which is really not that
interesting here.
The refcount_t: addition on 0 warning that must precede it would be
stronger evidence, as in the IPv6 commit.
So this looks like a modified kernel or something like AI hallucination ?
Please elaborate
pw-bot: cr
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device
2026-10-09 6:54 ` Eric Dumazet
@ 2026-10-09 8:16 ` Cen Zhang
0 siblings, 0 replies; 3+ messages in thread
From: Cen Zhang @ 2026-10-09 8:16 UTC (permalink / raw)
To: Eric Dumazet
Cc: dsahern, idosch, davem, kuba, pabeni, horms, jiri, netdev,
linux-kernel, baul.lee, baijiaju1990, jjzuming
Hi Eric,
Eric Dumazet <edumazet@kernel.org> 于2026年10月9日周五 14:54写道:
>
> This is very confusing.
> The changelog shows only the KASAN splat, which is really not that
> interesting here.
> The refcount_t: addition on 0 warning that must precede it would be
> stronger evidence, as in the IPv6 commit.
>
> So this looks like a modified kernel or something like AI hallucination ?
> Please elaborate
>
> pw-bot: cr
To Answer the robot's questions. I found this issue through
AI-assisted code analysis,
then built a test case to actually triggered it. I were not aware
of Baul's earlier submission at that point. The triggering run first reported:
------------[ cut here ]------------
refcount_t: addition on 0; use-after-free.
WARNING: lib/refcount.c:25 at refcount_warn_saturate+0xea/0x110,
CPU#1: ip_core_fixture/498
CPU: 1 UID: 0 PID: 498 Comm: ip_core_fixture Not tainted
7.2.0-rc5-pmb-bt-functional-v1+ #1 PREEMPT(lazy)
RIP: 0010:refcount_warn_saturate+0xea/0x110
Call Trace:
<TASK>
inet_netconf_get_devconf+0xcbc/0xe40
? __pfx_inet_netconf_get_devconf+0x10/0x10
rtnetlink_rcv_msg+0x7b9/0xce0
[...]
Best regards,
Cen Zhang
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-09 8:16 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09 6:21 [PATCH net v2] ipv4: prevent in_dev_get() from returning a dead in_device Cen Zhang
2026-10-09 6:54 ` Eric Dumazet
2026-10-09 8:16 ` Cen Zhang
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®