xfrm6: fix inet6_dev refcount underflow problem
authorZhang Changzhong <zhangchangzhong@huawei.com>
Fri, 15 Sep 2023 11:20:41 +0000 (19:20 +0800)
committerSteffen Klassert <steffen.klassert@secunet.com>
Wed, 20 Sep 2023 11:03:59 +0000 (13:03 +0200)
commitcc9b364bb1d58d3dae270c7a931a8cc717dc2b3b
treeccebe938507b2b4f1312c85f1ab5589e7c0798ec
parent3e4bc23926b83c3c67e5f61ae8571602754131a6
xfrm6: fix inet6_dev refcount underflow problem

There are race conditions that may lead to inet6_dev refcount underflow
in xfrm6_dst_destroy() and rt6_uncached_list_flush_dev().

One of the refcount underflow bugs is shown below:
(cpu 1)                 | (cpu 2)
xfrm6_dst_destroy()             |
  ...                           |
  in6_dev_put()                 |
|  rt6_uncached_list_flush_dev()
  ... |    ...
|    in6_dev_put()
  rt6_uncached_list_del()       |    ...
  ...                           |

xfrm6_dst_destroy() calls rt6_uncached_list_del() after in6_dev_put(),
so rt6_uncached_list_flush_dev() has a chance to call in6_dev_put()
again for the same inet6_dev.

Fix it by moving in6_dev_put() after rt6_uncached_list_del() in
xfrm6_dst_destroy().

Fixes: 510c321b5571 ("xfrm: reuse uncached_list to track xdsts")
Signed-off-by: Zhang Changzhong <zhangchangzhong@huawei.com>
Reviewed-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
net/ipv6/xfrm6_policy.c