diff options
| author | Bryam Vargas <hexlabsecurity@proton.me> | 2026-07-05 22:24:36 -0500 |
|---|---|---|
| committer | Paolo Abeni <pabeni@redhat.com> | 2026-07-10 16:24:43 +0200 |
| commit | 4fa349156043dc119721d067329714179f501749 (patch) | |
| tree | 39e4f1b0afa78cd461c8a51293879d5e8b66f985 /tools/perf/scripts/python/parallel-perf.py | |
| parent | f2f152e94a67bc746afaf05a1b2702c195553112 (diff) | |
net/iucv: take a reference on the socket found in afiucv_hs_rcv()
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Hidayath Khan <hidayath@linux.ibm.com>
Link: https://patch.msgid.link/20260705-b4-disp-fc79c0dc-v1-1-d2cdcb57afa9@proton.me
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Diffstat (limited to 'tools/perf/scripts/python/parallel-perf.py')
0 files changed, 0 insertions, 0 deletions
