]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
ovpn: hold peer before scheduling keepalive work
authorShuvam Pandey <shuvampandey1@gmail.com>
Sat, 23 May 2026 14:53:27 +0000 (20:38 +0545)
committerAntonio Quartulli <antonio@openvpn.net>
Mon, 20 Jul 2026 13:49:55 +0000 (15:49 +0200)
ovpn_peer_keepalive_send() passes its peer reference to
ovpn_xmit_special(), which ultimately drops it. The keepalive scheduler
currently queues the work first and takes the reference only after
schedule_work() reports that the work was queued.

Once schedule_work() queues the item, another CPU may run the worker
before the caller gets to ovpn_peer_hold(). In that case the worker can
consume a reference that was not acquired for it, corrupting the peer
lifetime accounting.

Take the peer reference before queueing the work and drop it again when
the work was already pending.

Fixes: 3ecfd9349f40 ("ovpn: implement keepalive mechanism")
Cc: stable@vger.kernel.org
Signed-off-by: Shuvam Pandey <shuvampandey1@gmail.com>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
drivers/net/ovpn/peer.c

index 1844d97154cea7278a607ef321a716c967fcb8f9..2b6096d8b1cc91437177c4a7ef24bc752fb685d2 100644 (file)
@@ -1284,8 +1284,10 @@ static time64_t ovpn_peer_keepalive_work_single(struct ovpn_peer *peer,
                netdev_dbg(peer->ovpn->dev,
                           "sending keepalive to peer %u\n",
                           peer->id);
-               if (schedule_work(&peer->keepalive_work))
-                       ovpn_peer_hold(peer);
+               if (WARN_ON(!ovpn_peer_hold(peer)))
+                       return 0;
+               if (!schedule_work(&peer->keepalive_work))
+                       ovpn_peer_put(peer);
        }
 
        if (next_run1 < next_run2)