net/smc: fix use-after-free in smc_rx_pipe_buf_release()
authorHidayath Khan <hidayath@linux.ibm.com>
Thu, 20 Aug 2026 07:46:42 +0000 (09:46 +0200)
committerJakub Kicinski <kuba@kernel.org>
Mon, 24 Aug 2026 18:52:00 +0000 (11:52 -0700)
smc_rx_splice() hands RMB pages to a pipe and takes a socket reference
per entry so the smc_sock stays alive until the reader finishes. The
connection does not: a concurrent close runs smc_conn_free(), which
releases the receive buffer back to the link group pool.

smc_rx_pipe_buf_release() tests sk_state before taking the socket lock.
The state can change between the test and the lock, and
smc_rx_update_cons() then dereferences conn->rmb_desc and walks
conn->lgr, which smc_conn_free() has already released. On the
is_reg_err path smcr_buf_unuse() frees the descriptor outright, so
this is a use-after-free.

Take the socket lock first and test conn->freed instead.
smc_conn_free() sets that flag before releasing anything, and every
caller holds the socket lock. The two paths exclude each other: either
the pipe release runs first with everything valid, or it sees the flag
and skips the update.

Fixes: 9014db202cb7 ("smc: add support for splice()")
Cc: stable@vger.kernel.org
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260820074642.966856-3-hidayath@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/smc/smc_rx.c

index 5c9e4d8..197fddc 100644 (file)
@@ -115,16 +115,15 @@ static void smc_rx_pipe_buf_release(struct pipe_inode_info *pipe,
                                    struct pipe_buffer *buf)
 {
        struct smc_spd_priv *priv = (struct smc_spd_priv *)buf->private;
+       struct smc_connection *conn = &priv->smc->conn;
        struct smc_sock *smc = priv->smc;
-       struct smc_connection *conn;
        struct sock *sk = &smc->sk;
 
-       if (sk->sk_state == SMC_CLOSED ||
-           sk->sk_state == SMC_PEERFINCLOSEWAIT ||
-           sk->sk_state == SMC_APPFINCLOSEWAIT)
-               goto out;
-       conn = &smc->conn;
        lock_sock(sk);
+       if (conn->freed) {
+               release_sock(sk);
+               goto out;
+       }
        smc_rx_update_cons(smc, priv->len);
        release_sock(sk);
        if (atomic_sub_and_test(priv->len, &conn->splice_pending))