Re: [PATCH net RESEND] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
From: patchwork-bot+netdevbpf
Date: Wed Sep 23 2026 - 23:11:35 EST
Hello:
This patch was applied to netdev/net.git (main)
by David Heidelberg <david@xxxxxxx>:
On Wed, 23 Sep 2026 10:33:39 -0300 you wrote:
> nfc_llcp_recv_dm() handles DM(NOBOUND)/DM(REJ) for a socket that is still
> linked on local->connecting_sockets: it looks the socket up with
> nfc_llcp_connecting_sock_get(), sets sk->sk_state = LLCP_CLOSED and
> returns, without taking the socket lock and without unlinking the socket
> from the connecting_sockets list.
>
> llcp_sock_release() selects the list to unlink from by sk_state: a socket
> in LLCP_CONNECTING is unlinked from connecting_sockets, otherwise from the
> sockets list. Because recv_dm left the socket physically on
> connecting_sockets but in the LLCP_CLOSED state, release() takes the else
> branch and calls nfc_llcp_sock_unlink(&local->sockets, sk). That runs
> sk_del_node_init() while holding sockets.lock, i.e. it removes the socket
> from the connecting_sockets hlist under the wrong lock. A concurrent
> connect() linking another socket onto connecting_sockets under
> connecting_sockets.lock then mutates the same hlist unserialized, which
> corrupts the list and desyncs the sk_add_node()/sk_del_node_init()
> sock_hold()/__sock_put() pairing. An unprivileged local process holding
> LLCP sockets, with the DM supplied by the remote peer over an established
> LLCP link, can drive this to leak kernel sockets without bound (the
> mis-decrement goes through the non-freeing __sock_put() path, so the
> object is never released), leading to memory exhaustion / DoS.
>
> [...]
Here is the summary with links:
- [net,RESEND] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
https://git.kernel.org/netdev/net/c/bf1460acdf8c
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html