]> git.hungrycats.org Git - linux/commitdiff
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
authorIbrahim Hashimov <security@auditcode.ai>
Sun, 12 Jul 2026 12:17:20 +0000 (14:17 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 2 Sep 2026 12:31:45 +0000 (14:31 +0200)
[ Upstream commit 6f7014237405e7f032b5c53a82d9eccf6161c291 ]

rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the
IB_QP_STATE path, so it holds no state_lock and runs while the responder
task rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting
only that attribute calls free_rd_atomic_resources() then
alloc_rd_atomic_resources(), swapping qp->resp.resources[] while
rxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources()
also leaves the cached pointer qp->resp.res dangling. A local
unprivileged user can race the free/realloc into a use-after-free in
rxe_receiver() (local DoS).

Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(),
as rxe_qp_reset() already does when tearing this array down, re-enabling
only after alloc_rd_atomic_resources() succeeds so the responder never
resumes against a NULL qp->resp.resources on the ENOMEM path. Also clear
qp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c
completion paths.

Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Link: https://patch.msgid.link/20260712121720.78001-1-security@auditcode.ai
Assisted-by: AuditCode-AI:2026.07
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/infiniband/sw/rxe/rxe_qp.c

index 95f1c1c2949de7778aeb9bc7890ba945b9ad1b3b..0af697c6469db3bd884a41d1c0000412cd0f3907 100644 (file)
@@ -124,6 +124,7 @@ static void free_rd_atomic_resources(struct rxe_qp *qp)
                }
                kfree(qp->resp.resources);
                qp->resp.resources = NULL;
+               qp->resp.res = NULL;
        }
 }
 
@@ -660,11 +661,23 @@ int rxe_qp_from_attr(struct rxe_qp *qp, struct ib_qp_attr *attr, int mask,
 
                qp->attr.max_dest_rd_atomic = max_dest_rd_atomic;
 
+               /*
+                * Not gated by IB_QP_STATE, so the responder task is live.
+                * Quiesce recv_task like rxe_qp_reset() before swapping the
+                * rd_atomic array, so rxe_receiver() cannot race the free/
+                * realloc.
+                */
+               rxe_disable_task(&qp->recv_task);
                free_rd_atomic_resources(qp);
-
                err = alloc_rd_atomic_resources(qp, max_dest_rd_atomic);
+               /*
+                * On ENOMEM leave recv_task quiesced: qp->resp.resources is
+                * NULL and rxe_prepare_res()/find_resource() would deref it.
+                * Re-enable only after a fresh array is installed.
+                */
                if (err)
                        return err;
+               rxe_enable_task(&qp->recv_task);
        }
 
        if (mask & IB_QP_EN_SQD_ASYNC_NOTIFY)