mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-14 06:22:34 +02:00
The x25 timers are armed with mod_timer() and cancelled with
timer_delete(), so a pending timer holds no reference on the socket and a
cancel does not wait for a callback already running on another CPU.
x25_heartbeat_expiry() also rearms unconditionally, so it can reinstall
sk->sk_timer after __x25_destroy_socket() has passed its cancel point.
The following __sock_put() frees the socket while the timer is still
queued, and the next expiry uses freed memory. KASAN reports a
slab-use-after-free on the kmalloc-2k object freed by close().
timer_delete_sync() cannot be used here: x25_heartbeat_expiry() and
x25_timer_expiry() both reach the cancels from inside the timer they
would wait on, through __x25_destroy_socket() and x25_disconnect().
Arm the timers with sk_reset_timer() and cancel them with sk_stop_timer()
so that an armed timer owns a reference, and release it in both expiry
handlers. Rearm the heartbeat only while sk_hashed(sk) is still true,
since __x25_destroy_socket() unlinks the socket before dropping it. Arm
the deferred destroy timer the same way and drop its reference in
x25_destroy_timer().
Reproduced on net with KASAN, with the heartbeat period shortened so the
window recurs. With this patch the reproducer no longer triggers a
report and /proc/net/x25 drains.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726220342.47245-1-baul.lee@xbow.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
177 lines
3.9 KiB
C
177 lines
3.9 KiB
C
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
/*
|
|
* X.25 Packet Layer release 002
|
|
*
|
|
* This is ALPHA test software. This code may break your machine,
|
|
* randomly fail to work with new releases, misbehave and/or generally
|
|
* screw up. It might even work.
|
|
*
|
|
* This code REQUIRES 2.1.15 or higher
|
|
*
|
|
* History
|
|
* X.25 001 Jonathan Naylor Started coding.
|
|
* X.25 002 Jonathan Naylor New timer architecture.
|
|
* Centralised disconnection processing.
|
|
*/
|
|
|
|
#include <linux/errno.h>
|
|
#include <linux/jiffies.h>
|
|
#include <linux/timer.h>
|
|
#include <net/sock.h>
|
|
#include <net/tcp_states.h>
|
|
#include <net/x25.h>
|
|
|
|
static void x25_heartbeat_expiry(struct timer_list *t);
|
|
static void x25_timer_expiry(struct timer_list *t);
|
|
|
|
void x25_init_timers(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
timer_setup(&x25->timer, x25_timer_expiry, 0);
|
|
|
|
/* initialized by sock_init_data */
|
|
sk->sk_timer.function = x25_heartbeat_expiry;
|
|
}
|
|
|
|
void x25_start_heartbeat(struct sock *sk)
|
|
{
|
|
sk_reset_timer(sk, &sk->sk_timer, jiffies + 5 * HZ);
|
|
}
|
|
|
|
void x25_stop_heartbeat(struct sock *sk)
|
|
{
|
|
sk_stop_timer(sk, &sk->sk_timer);
|
|
}
|
|
|
|
void x25_start_t2timer(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
sk_reset_timer(sk, &x25->timer, jiffies + x25->t2);
|
|
}
|
|
|
|
void x25_start_t21timer(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
sk_reset_timer(sk, &x25->timer, jiffies + x25->t21);
|
|
}
|
|
|
|
void x25_start_t22timer(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
sk_reset_timer(sk, &x25->timer, jiffies + x25->t22);
|
|
}
|
|
|
|
void x25_start_t23timer(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
sk_reset_timer(sk, &x25->timer, jiffies + x25->t23);
|
|
}
|
|
|
|
void x25_stop_timer(struct sock *sk)
|
|
{
|
|
sk_stop_timer(sk, &x25_sk(sk)->timer);
|
|
}
|
|
|
|
unsigned long x25_display_timer(struct sock *sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
if (!timer_pending(&x25->timer))
|
|
return 0;
|
|
|
|
return x25->timer.expires - jiffies;
|
|
}
|
|
|
|
static void x25_heartbeat_expiry(struct timer_list *t)
|
|
{
|
|
struct sock *sk = timer_container_of(sk, t, sk_timer);
|
|
|
|
bh_lock_sock(sk);
|
|
if (sock_owned_by_user(sk)) /* can currently only occur in state 3 */
|
|
goto restart_heartbeat;
|
|
|
|
switch (x25_sk(sk)->state) {
|
|
|
|
case X25_STATE_0:
|
|
/*
|
|
* Magic here: If we listen() and a new link dies
|
|
* before it is accepted() it isn't 'dead' so doesn't
|
|
* get removed.
|
|
*/
|
|
if (sock_flag(sk, SOCK_DESTROY) ||
|
|
(sk->sk_state == TCP_LISTEN &&
|
|
sock_flag(sk, SOCK_DEAD))) {
|
|
bh_unlock_sock(sk);
|
|
x25_destroy_socket_from_timer(sk);
|
|
goto out;
|
|
}
|
|
break;
|
|
|
|
case X25_STATE_3:
|
|
/*
|
|
* Check for the state of the receive buffer.
|
|
*/
|
|
x25_check_rbuf(sk);
|
|
break;
|
|
}
|
|
restart_heartbeat:
|
|
/* Do not rearm once __x25_destroy_socket() has unlinked the socket:
|
|
* it is past its cancel point and owns the teardown from there on.
|
|
*/
|
|
if (sk_hashed(sk))
|
|
x25_start_heartbeat(sk);
|
|
bh_unlock_sock(sk);
|
|
out:
|
|
sock_put(sk);
|
|
}
|
|
|
|
/*
|
|
* Timer has expired, it may have been T2, T21, T22, or T23. We can tell
|
|
* by the state machine state.
|
|
*/
|
|
static inline void x25_do_timer_expiry(struct sock * sk)
|
|
{
|
|
struct x25_sock *x25 = x25_sk(sk);
|
|
|
|
switch (x25->state) {
|
|
|
|
case X25_STATE_3: /* T2 */
|
|
if (x25->condition & X25_COND_ACK_PENDING) {
|
|
x25->condition &= ~X25_COND_ACK_PENDING;
|
|
x25_enquiry_response(sk);
|
|
}
|
|
break;
|
|
|
|
case X25_STATE_1: /* T21 */
|
|
case X25_STATE_4: /* T22 */
|
|
x25_write_internal(sk, X25_CLEAR_REQUEST);
|
|
x25->state = X25_STATE_2;
|
|
x25_start_t23timer(sk);
|
|
break;
|
|
|
|
case X25_STATE_2: /* T23 */
|
|
x25_disconnect(sk, ETIMEDOUT, 0, 0);
|
|
break;
|
|
}
|
|
}
|
|
|
|
static void x25_timer_expiry(struct timer_list *t)
|
|
{
|
|
struct x25_sock *x25 = timer_container_of(x25, t, timer);
|
|
struct sock *sk = &x25->sk;
|
|
|
|
bh_lock_sock(sk);
|
|
if (sock_owned_by_user(sk)) { /* can currently only occur in state 3 */
|
|
if (x25_sk(sk)->state == X25_STATE_3)
|
|
x25_start_t2timer(sk);
|
|
} else
|
|
x25_do_timer_expiry(sk);
|
|
bh_unlock_sock(sk);
|
|
sock_put(sk);
|
|
}
|