> On Feb 8, 2023, at 1:44 PM, Paolo Abeni <pabeni@redhat.com> wrote:
>
> Sharing these very early, because I can't reproduce the issues locally.
> Even the commit messages are early draft.
>
> @Christoph could you please check the relevant repros here?
>
> I *think* there still some refcount problem to address in the new code,
> any sharp eyes more then welcome ;)
>
> Targeting -net even if bases on top of corrent mptcp-next, as
> the merge window is almost imminent.
>
> Paolo Abeni (2):
> mptcp: use the workqueue to destroy unaccepted sockets.
> mptcp: fix UaF in listener shutdown
>
> net/mptcp/protocol.c | 27 ++++++++-----
> net/mptcp/protocol.h | 4 +-
> net/mptcp/subflow.c | 91 +++++---------------------------------------
> 3 files changed, 28 insertions(+), 94 deletions(-)
I was able to get a new reproducer for a UaF read in subflow_error_report.
Your patches (with the schedule-work fix) indeed fix the KASAN-issue.
Tested-by: Christoph Paasch <cpaasch@apple.com>
Christoph