| From 910a378bf26fb82568e55b4eff263e4d77cd8854 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 3 Sep 2026 10:35:11 +0200 |
| Subject: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount |
| |
| From: Matthieu Baerts (NGI0) <matttbe@kernel.org> |
| |
| [ Upstream commit 9634cb35af17019baec21ca648516ce376fa10e6 ] |
| |
| When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). |
| It should then be released in all cases at the end. |
| |
| Some (unlikely) checks were returning directly instead of calling |
| sock_put() to decrease the refcount. Jump to a new 'exit' label to call |
| __sock_put() (which will become sock_put() in the next commit) to fix |
| this potential leak. |
| |
| While at it, drop the '!msk' check which cannot happen because it is |
| never reset, and explicitly mark the remaining one as "unlikely". |
| |
| Fixes: 00cfd77b9063 ("mptcp: retransmit ADD_ADDR when timeout") |
| Cc: stable@vger.kernel.org |
| Reviewed-by: Mat Martineau <martineau@kernel.org> |
| Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> |
| Link: https://patch.msgid.link/20260505-net-mptcp-pm-fixes-7-1-rc3-v1-4-fca8091060a4@kernel.org |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| [ Karl Mehltretter: applied to pm_netlink.c; retained v5.10's ID 0 guard |
| and routed it through the common refcount drop. ] |
| Assisted-by: LLM |
| Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/mptcp/pm_netlink.c | 10 ++++------ |
| 1 file changed, 4 insertions(+), 6 deletions(-) |
| |
| diff --git a/net/mptcp/pm_netlink.c b/net/mptcp/pm_netlink.c |
| index d4d56f0af3e0a..aee3a8dd9287a 100644 |
| --- a/net/mptcp/pm_netlink.c |
| +++ b/net/mptcp/pm_netlink.c |
| @@ -217,14 +217,11 @@ static void mptcp_pm_add_timer(struct timer_list *timer) |
| |
| pr_debug("msk=%p\n", msk); |
| |
| - if (!msk) |
| - return; |
| - |
| - if (inet_sk_state_load(sk) == TCP_CLOSE) |
| - return; |
| + if (unlikely(inet_sk_state_load(sk) == TCP_CLOSE)) |
| + goto exit; |
| |
| if (!entry->addr.id) |
| - return; |
| + goto exit; |
| |
| bh_lock_sock(sk); |
| if (sock_owned_by_user(sk)) { |
| @@ -253,6 +250,7 @@ static void mptcp_pm_add_timer(struct timer_list *timer) |
| |
| out: |
| bh_unlock_sock(sk); |
| +exit: |
| __sock_put(sk); |
| } |
| |
| -- |
| 2.53.0 |
| |