mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 08:15:07 -04:00
RDMA/core: Fix potential use after free in ib_free_cq()
When accessing a CQ via the netlink path the only synchronization
mechanism for the said CQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_free_cq(), which is too late, since by that point
vendor-specific resources associated with the CQ might already be
freed. This can leave a short window where the CQ remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_del() call to be before the freeing
of the vendor-specific resources ensuring that the CQ is removed from
restrack before its internal resources are released.
This guarantees that no new users hold references to a CQ that is in
the process of destruction.
Fixes: 43d781b9fa ("RDMA: Allow fail of destroy CQ")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-6-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
This commit is contained in:
committed by
Leon Romanovsky
parent
235ef2d0e7
commit
29dc2f8e1c
@@ -327,6 +327,7 @@ void ib_free_cq(struct ib_cq *cq)
|
||||
if (WARN_ON_ONCE(cq->cqe_used))
|
||||
return;
|
||||
|
||||
rdma_restrack_del(&cq->res);
|
||||
if (cq->device->ops.pre_destroy_cq) {
|
||||
ret = cq->device->ops.pre_destroy_cq(cq);
|
||||
WARN_ONCE(ret, "Disable of kernel CQ shouldn't fail");
|
||||
@@ -353,7 +354,6 @@ void ib_free_cq(struct ib_cq *cq)
|
||||
else
|
||||
ret = cq->device->ops.destroy_cq(cq, NULL);
|
||||
WARN_ONCE(ret, "Destroy of kernel CQ shouldn't fail");
|
||||
rdma_restrack_del(&cq->res);
|
||||
kfree(cq->wc);
|
||||
kfree(cq);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user