summaryrefslogtreecommitdiffstats
path: root/drivers
diff options
context:
space:
mode:
authorDae R. Jeong <threeearcat@gmail.com>2024-05-21 19:34:38 +0900
committerPaolo Abeni <pabeni@redhat.com>2024-05-23 12:03:26 +0200
commit91e61dd7a0af660408e87372d8330ceb218be302 (patch)
tree69bc4696c019ef04ef22c34400827fd86e7ffbbe /drivers
parent3b1c92f8e5371700fada307cc8fd2c51fa7bc8c1 (diff)
downloadlinux-stable-91e61dd7a0af660408e87372d8330ceb218be302.tar.gz
linux-stable-91e61dd7a0af660408e87372d8330ceb218be302.tar.bz2
linux-stable-91e61dd7a0af660408e87372d8330ceb218be302.zip
tls: fix missing memory barrier in tls_init
In tls_init(), a write memory barrier is missing, and store-store reordering may cause NULL dereference in tls_{setsockopt,getsockopt}. CPU0 CPU1 ----- ----- // In tls_init() // In tls_ctx_create() ctx = kzalloc() ctx->sk_proto = READ_ONCE(sk->sk_prot) -(1) // In update_sk_prot() WRITE_ONCE(sk->sk_prot, tls_prots) -(2) // In sock_common_setsockopt() READ_ONCE(sk->sk_prot)->setsockopt() // In tls_{setsockopt,getsockopt}() ctx->sk_proto->setsockopt() -(3) In the above scenario, when (1) and (2) are reordered, (3) can observe the NULL value of ctx->sk_proto, causing NULL dereference. To fix it, we rely on rcu_assign_pointer() which implies the release barrier semantic. By moving rcu_assign_pointer() after ctx->sk_proto is initialized, we can ensure that ctx->sk_proto are visible when changing sk->sk_prot. Fixes: d5bee7374b68 ("net/tls: Annotate access to sk_prot with READ_ONCE/WRITE_ONCE") Signed-off-by: Yewon Choi <woni9911@gmail.com> Signed-off-by: Dae R. Jeong <threeearcat@gmail.com> Link: https://lore.kernel.org/netdev/ZU4OJG56g2V9z_H7@dragonet/T/ Link: https://lore.kernel.org/r/Zkx4vjSFp0mfpjQ2@libra05 Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Diffstat (limited to 'drivers')
0 files changed, 0 insertions, 0 deletions