]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
nfc: rawsock: cancel tx_work before socket teardown
authorJakub Kicinski <kuba@kernel.org>
Tue, 3 Mar 2026 16:23:45 +0000 (08:23 -0800)
committerJakub Kicinski <kuba@kernel.org>
Thu, 5 Mar 2026 02:18:57 +0000 (18:18 -0800)
commitd793458c45df2aed498d7f74145eab7ee22d25aa
treefc124196aee5c0e9c1f3357273ff02aef16d9124
parent0efdc02f4f6d52f8ca5d5889560f325a836ce0a8
nfc: rawsock: cancel tx_work before socket teardown

In rawsock_release(), cancel any pending tx_work and purge the write
queue before orphaning the socket.  rawsock_tx_work runs on the system
workqueue and calls nfc_data_exchange which dereferences the NCI
device.  Without synchronization, tx_work can race with socket and
device teardown when a process is killed (e.g. by SIGKILL), leading
to use-after-free or leaked references.

Set SEND_SHUTDOWN first so that if tx_work is already running it will
see the flag and skip transmitting, then use cancel_work_sync to wait
for any in-progress execution to finish, and finally purge any
remaining queued skbs.

Fixes: 23b7869c0fd0 ("NFC: add the NFC socket raw protocol")
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260303162346.2071888-6-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/nfc/rawsock.c