Page MenuHomeFreeBSD

sctp: Hold association locks across socket wakeups when freeing
ClosedPublic

Authored by markj on Aug 31 2021, 4:18 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Dec 20, 5:21 AM
Unknown Object (File)
Fri, Dec 12, 4:36 PM
Unknown Object (File)
Nov 27 2025, 1:31 AM
Unknown Object (File)
Nov 17 2025, 3:05 AM
Unknown Object (File)
Nov 17 2025, 3:05 AM
Unknown Object (File)
Nov 17 2025, 3:05 AM
Unknown Object (File)
Nov 17 2025, 1:24 AM
Unknown Object (File)
Nov 10 2025, 9:12 AM
Subscribers

Details

Summary

At this point we do not hold the inpcb lock, so the only thing holding
the socket reference live is the TCB lock, which needs to be acquired by
sctp_inpcb_free() in order to destroy associations. Defer the unlock
until after we dereference the socket reference.

Reported by: syzbot+1d0f2c4675de76a4cf1e@syzkaller.appspotmail.com
Reported by: syzbot+fabee77954fe69d3a5ad@syzkaller.appspotmail.com

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 41295
Build 38184: arc lint + arc unit