]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
authorHidayath Khan <hidayath@linux.ibm.com>
Thu, 9 Jul 2026 19:17:32 +0000 (21:17 +0200)
committerJakub Kicinski <kuba@kernel.org>
Tue, 21 Jul 2026 20:36:35 +0000 (13:36 -0700)
afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.
If the allocation fails, nsk is NULL.

The connection-refused path is entered when the listen state check
fails, the accept backlog is full, or nsk is NULL. The code
unconditionally calls iucv_sock_kill(nsk) in that path.

iucv_sock_kill() does not accept a NULL socket pointer and immediately
dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,
calling iucv_sock_kill(nsk) results in a NULL pointer dereference.

Only call iucv_sock_kill() when a child socket was successfully
allocated.

Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport")
Cc: stable@vger.kernel.org
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
Link: https://patch.msgid.link/20260709191732.124092-1-hidayath@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/iucv/af_iucv.c

index e3e71d168c47fdac57c3e42287bb6eab37293618..ea047bab65e7c5a29cf42e58856619a4749bc82a 100644 (file)
@@ -1886,7 +1886,8 @@ static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
                afiucv_swap_src_dest(skb);
                trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
                err = dev_queue_xmit(skb);
-               iucv_sock_kill(nsk);
+               if (nsk)
+                       iucv_sock_kill(nsk);
                bh_unlock_sock(sk);
                goto out;
        }