Skip to content

Commit f6db909

Browse files
lxindavem330
authored andcommitted
tipc: call rcu_read_lock() in tipc_aead_encrypt_done()
b->media->send_msg() requires rcu_read_lock(), as we can see elsewhere in tipc, tipc_bearer_xmit, tipc_bearer_xmit_skb and tipc_bearer_bc_xmit(). Syzbot has reported this issue as: net/tipc/bearer.c:466 suspicious rcu_dereference_check() usage! Workqueue: cryptd cryptd_queue_worker Call Trace: tipc_l2_send_msg+0x354/0x420 net/tipc/bearer.c:466 tipc_aead_encrypt_done+0x204/0x3a0 net/tipc/crypto.c:761 cryptd_aead_crypt+0xe8/0x1d0 crypto/cryptd.c:739 cryptd_queue_worker+0x118/0x1b0 crypto/cryptd.c:181 process_one_work+0x94c/0x1670 kernel/workqueue.c:2269 worker_thread+0x64c/0x1120 kernel/workqueue.c:2415 kthread+0x3b5/0x4a0 kernel/kthread.c:291 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:293 So fix it by calling rcu_read_lock() in tipc_aead_encrypt_done() for b->media->send_msg(). Fixes: fc1b6d6 ("tipc: introduce TIPC encryption & authentication") Reported-by: [email protected] Signed-off-by: Xin Long <[email protected]> Signed-off-by: David S. Miller <[email protected]>
1 parent eda814b commit f6db909

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

net/tipc/crypto.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -757,10 +757,12 @@ static void tipc_aead_encrypt_done(struct crypto_async_request *base, int err)
757757
switch (err) {
758758
case 0:
759759
this_cpu_inc(tx->stats->stat[STAT_ASYNC_OK]);
760+
rcu_read_lock();
760761
if (likely(test_bit(0, &b->up)))
761762
b->media->send_msg(net, skb, b, &tx_ctx->dst);
762763
else
763764
kfree_skb(skb);
765+
rcu_read_unlock();
764766
break;
765767
case -EINPROGRESS:
766768
return;

0 commit comments

Comments
 (0)