Re: [PATCH 6/7] RDMA/siw: Fix new_cep use-after-free in siw_accept_newconn()
From: Leon Romanovsky
Date: Wed Sep 23 2026 - 04:11:10 EST
On Wed, Sep 16, 2026 at 06:41:09PM +0000, Wentao Liang wrote:
> On the error path the listening endpoint reference of new_cep is
> dropped before the accepted socket is disassociated. When only the
> socket's reference remains, siw_socket_disassoc() drops that last
> reference and frees the endpoint, leaving the subsequent
> 'new_cep->sock = NULL' writing into freed memory.
>
> Tear the accepted socket down first and put the endpoint last.
>
> Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>
> ---
> drivers/infiniband/sw/siw/siw_cm.c | 10 ++++++----
> 1 file changed, 6 insertions(+), 4 deletions(-)
I think this patch is supposed to fix it:
https://patch.msgid.link/r/20260604160808.30948-1-bernard.metzler@xxxxxxxxx
Thanks
>
> diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
> index f7ac81c0f267..1b93963cb191 100644
> --- a/drivers/infiniband/sw/siw/siw_cm.c
> +++ b/drivers/infiniband/sw/siw/siw_cm.c
> @@ -1044,14 +1044,16 @@ static void siw_accept_newconn(struct siw_cep *cep)
> return;
>
> error:
> - if (new_cep)
> - siw_cep_put(new_cep);
> -
> if (new_s) {
> siw_socket_disassoc(new_s);
> sock_release(new_s);
> - new_cep->sock = NULL;
> + if (new_cep)
> + new_cep->sock = NULL;
> }
> +
> + if (new_cep)
> + siw_cep_put(new_cep);
> +
> siw_dbg_cep(cep, "error %d\n", rv);
> }
>
> --
> 2.34.1
>