]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
vsock/vmci: fix sk_ack_backlog leak on failed handshake
authorRaf Dickson <rafdog35@gmail.com>
Tue, 26 May 2026 10:43:56 +0000 (10:43 +0000)
committerPaolo Abeni <pabeni@redhat.com>
Thu, 4 Jun 2026 11:08:02 +0000 (13:08 +0200)
When vmci_transport_recv_connecting_server() returns an error,
vmci_transport_recv_listen() calls vsock_remove_pending() but never
calls sk_acceptq_removed(). This leaves sk_ack_backlog incremented
permanently.

Repeated handshake failures (malformed packets, queue pair alloc
failure, event subscribe failure) cause sk_ack_backlog to climb
toward sk_max_ack_backlog. Once it reaches the limit the listener
permanently refuses all new connections with -ECONNREFUSED, a
silent denial of service requiring a process restart to recover.

The two existing sk_acceptq_removed() calls in af_vsock.c do not
cover this path: line 764 checks vsock_is_pending() which returns
false after vsock_remove_pending(), and line 1889 is only reached
on successful accept().

Fix by balancing sk_acceptq_added() with sk_acceptq_removed() on
the error path.

Fixes: d021c344051a ("VSOCK: Introduce VM Sockets")
Cc: stable@vger.kernel.org
Signed-off-by: Raf Dickson <rafdog35@gmail.com>
Acked-by: Stefano Garzarella <sgarzare@redhat.com>
Link: https://patch.msgid.link/20260526104356.469928-1-rafdog35@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
net/vmw_vsock/vmci_transport.c

index 5c1ecd5bfdbc2131233249caf8589e410a1548d2..91516488a742ad63ebe6ef9bc58f947acd304695 100644 (file)
@@ -980,8 +980,10 @@ static int vmci_transport_recv_listen(struct sock *sk,
                        err = -EINVAL;
                }
 
-               if (err < 0)
+               if (err < 0) {
                        vsock_remove_pending(sk, pending);
+                       sk_acceptq_removed(sk);
+               }
 
                release_sock(pending);
                vmci_transport_release_pending(pending);