[PATCH v2] rxrpc: Put aborted conn for challenge packet
Edward Adam Davis
eadavis at sina.com
Sun Sep 27 20:00:39 PDT 2026
RxRPC aborts the connection if the secure connection establishment fails.
Subsequently, receiving a challenge-type packet on the aborted connection
does not put the connection, this causes an imbalance in the connection's
reference count, potentially hitting:
kernel BUG at net/rxrpc/conn_client.c:64!
RIP: 0010:rxrpc_destroy_client_conn_ids net/rxrpc/conn_client.c:64 [inline]
RIP: 0010:rxrpc_purge_client_connections+0xc0/0x1a0 net/rxrpc/conn_client.c:145
Call Trace:
rxrpc_destroy_local+0x262/0x300 net/rxrpc/local_object.c:451
rxrpc_io_thread+0x2e1a/0x3820 net/rxrpc/io_thread.c:579
Put the connection before returning when processing a received challenge
packet.
Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Reported-by: syzbot+e2f5927fc701355ef101 at syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e2f5927fc701355ef101
Tested-by: syzbot+e2f5927fc701355ef101 at syzkaller.appspotmail.com
Signed-off-by: Edward Adam Davis <eadavis at sina.com>
---
v1 -> v2: put aborted conn for challenge packet
net/rxrpc/conn_event.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/net/rxrpc/conn_event.c b/net/rxrpc/conn_event.c
index 611c790bc6d0..f9af07d7db4a 100644
--- a/net/rxrpc/conn_event.c
+++ b/net/rxrpc/conn_event.c
@@ -272,14 +272,15 @@ static int rxrpc_process_event(struct rxrpc_connection *conn,
bool secured = false;
int ret;
- if (conn->state == RXRPC_CONN_ABORTED)
- return -ECONNABORTED;
_enter("{%d},{%u,%%%u},", conn->debug_id, sp->hdr.type, sp->hdr.serial);
switch (sp->hdr.type) {
case RXRPC_PACKET_TYPE_CHALLENGE:
- ret = conn->security->respond_to_challenge(conn, skb);
+ if (conn->state != RXRPC_CONN_ABORTED)
+ ret = conn->security->respond_to_challenge(conn, skb);
+ else
+ ret = -ECONNABORTED;
sp->chall.conn = NULL;
rxrpc_put_connection(conn, rxrpc_conn_put_challenge_input);
return ret;
@@ -323,6 +324,8 @@ static int rxrpc_process_event(struct rxrpc_connection *conn,
return 0;
default:
+ if (conn->state == RXRPC_CONN_ABORTED)
+ return -ECONNABORTED;
WARN_ON_ONCE(1);
return -EPROTO;
}
--
2.43.0
More information about the linux-afs
mailing list