• Jiri Pirko's avatar
    net: sched: fix use-after-free in tcf_action_destroy and tcf_del_walker · 255cd50f
    Jiri Pirko authored
    Recent commit d7fb60b9 ("net_sched: get rid of tcfa_rcu") removed
    freeing in call_rcu, which changed already existing hard-to-hit
    race condition into 100% hit:
    
    [  598.599825] BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
    [  598.607782] IP: tcf_action_destroy+0xc0/0x140
    
    Or:
    
    [   40.858924] BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
    [   40.862840] IP: tcf_generic_walker+0x534/0x820
    
    Fix this by storing the ops and use them directly for module_put call.
    
    Fixes: a85a970a ("net_sched: move tc_action into tcf_common")
    Signed-off-by: default avatarJiri Pirko <[email protected]>
    Signed-off-by: default avatarDavid S. Miller <[email protected]>
    255cd50f
act_api.c 27.6 KB