]> git.ipfire.org Git - thirdparty/linux.git/commit
net: smc: fix splice entry lifetime imbalance in smc_rx_splice
authorDaming Li <d4n.for.sec@gmail.com>
Thu, 30 Jul 2026 14:55:52 +0000 (22:55 +0800)
committerJakub Kicinski <kuba@kernel.org>
Tue, 4 Aug 2026 01:27:51 +0000 (18:27 -0700)
commit5d9686af2976741bbd79b150d1c9e60b81e7f12e
tree72333c387a008f26b0ef9995e0066d6ad5d85b3a
parent1cb4298810e27e037d3ca07286ecbb97e89ba58d
net: smc: fix splice entry lifetime imbalance in smc_rx_splice

smc_rx_splice() passes pages to splice_to_pipe() before taking the
references that cover the lifetime of each splice entry. In the
VM-backed RMB path, splice_to_pipe() may drop unqueued entries through
smc_rx_spd_release(), while queued entries are released later via the
pipe buffer callback.

The old post-splice accounting also derives the number of queued VM pages
from an offset mutated while building the descriptor, and a multi-page
splice pairs one sock_hold() with multiple sock_put() calls.

Take the page and socket references for every candidate entry before
splice_to_pipe(), and drop the matching private state, page reference,
and socket reference from smc_rx_spd_release() for entries that never
get queued. This fixes a refcount imbalance that can underflow page
refcounts and trigger a use-after-free.

Fixes: 9014db202cb7 ("smc: add support for splice()")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Co-developed-by: Xiao Liu <lx24@stu.ynu.edu.cn>
Signed-off-by: Xiao Liu <lx24@stu.ynu.edu.cn>
Signed-off-by: Daming Li <d4n.for.sec@gmail.com>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Reviewed-by: Sidraya Jayagond <sidraya@linux.ibm.com>
Link: https://patch.msgid.link/20260730145552.360287-2-enjou1224z@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/smc/smc_rx.c