From nobody Sat Jul 25 20:05:57 2026 Received: from mail-qk1-f172.google.com (mail-qk1-f172.google.com [209.85.222.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF1B32E173D for ; Tue, 14 Jul 2026 07:06:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784012776; cv=none; b=bwl9gzh+biV429nrTRnq6Uw5b7M5AFgiCvQPbChW5Y5DB6sPpzi4qdm3XJMkwTZ+nTi2WIeds9sV8ZNVu/zCSMINh5c5FC8G9L3hFYS4o0mrJDQqNsWuUCAP7f8l34190Mv+oTlvX2zWdOlrKAW836pSKprf2Z71vwWTMumD8p8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784012776; c=relaxed/simple; bh=dgAaCvJUgNsbJbDV3QNxqapNCHCjbfQrCWzRi8Y0MZs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=cxdr/cumoXC52yl3D544jkG5s/FMyfygh/Ic5gZlJ12EKBoUK2FmOw+nJ3urDImqNfZZrtk787unN2ycWkIOgF6eD8i15HCEUfF/M+1hQ/h8b0bzXFGzvvfjTk08nUZtEf9oYrNqzhPNK8/k7YSUz/I3P03FuyMnFs2SKatht8I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=SqcYW6sB; arc=none smtp.client-ip=209.85.222.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="SqcYW6sB" Received: by mail-qk1-f172.google.com with SMTP id af79cd13be357-92e5cb052edso54010585a.2 for ; Tue, 14 Jul 2026 00:06:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1784012774; x=1784617574; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=6g9ahD4oG1/R4wtuY0Np/xYwVS3jEMB1YAMnOuBleng=; b=SqcYW6sBj4tzygAnXs+/fT+Vj2EBTHQ9D6l2yc0m3cktWKY3gyq87LHgK/yKSydvOP izAEruRsv7JvZJpZ/yXwgq6H4/hVSYl01V31yf94rBQ0n2cRpFydUV2LQ0GmkNLBd+MU Z0VGZqZ08wCSHi8L0YqNf9R+FbcP3oFE5LSQsoIsBoccO0k37L8rmlx+clU2j8gnBLGR f8pwqU043nBtdv8Suc0PHD1u61GFlnZ10J67LkUR5Fy7eLs0fE8F0kVMDYbgtMBXMZOj isgLACVSzdNjerGmBgdf338EmYoam9dmXY9182qWsyoCa1pixclr9JmViSnu+nBKMeOK 69ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784012774; x=1784617574; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6g9ahD4oG1/R4wtuY0Np/xYwVS3jEMB1YAMnOuBleng=; b=Aqvbeo3BKDgC5a9cS0Cy1Ax3oyTLdOlBxxCnDaQ1xY8aFStTjFpaMbq+9fJ+NFpAI9 lqrTinpQ2cZ6CafJVQXqSgKaW9NL9LHfR82TebXffVEtoUi3QbqDdruH97TDK0jBEKIK EvJe5vu1eOECeqADqN0MgDXOYOhAlzrxQ5pJGWPkjPTTYEumN3z4C4O/3T0J7iw/XFuZ fomx6BOA+r1uTt4A4Z6C6/OnZ0YPuGoBO6kD5QMtjbCZuXVYwmEzYUbL7HlfpAExZ8da +w+vnPXd8rwHefkLjIeRTRLIs0a62rtEzVfvA7o+kDr6cgMAKFTXS6/8GaZmyOcp4cBS Od6A== X-Forwarded-Encrypted: i=1; AHgh+RpsS4xPbnlKc++KN5nx3sOugE2kAOZ0I3PdX4PaCw+SnsT3j10U0ao1hVEVyQRwzCXxUaA5txCEF15d6pU=@vger.kernel.org X-Gm-Message-State: AOJu0Yxy4Xz6mzNy7EEMpY4PDi24QFVTO6yrz4/5pqqk/F4nN9dskmaf M9+wEDSKb838jqMMqojAxhn9MHgjPR1srv2dEYdbTtaTf6aSlVAM8vEwP5sJmXi0Zf4= X-Gm-Gg: AfdE7ck4/TtLm8+WdZfVRkZVYGELLmzSg4OV4lXDWZlmn9qWz0Qu7ZiIe/0HLGTSvtL YuKrwabO5CZjfNR5XJK5nZNsmOhF/rHAAG2nOjFdT8/7G6o864BkSmD6HaygM8LSEEJZsBYTe0I CseareIbqo8RNgccmzSlqDsbtdPBUQO0alxrUBMq5HwbJXFiuG1v2Y7QRUla8PVkc1rjFDU5mE1 aTTv0xSBqaLauFIPfiak21W5KBQw9AR9BWZPsAHOSjax2gb2ZmpmBwrMpDo/+Co29KBvMuYxTzz Xu9JhT0LHJ3GqY6Xhqxs9TG9RyybGEP+Tf6EJkWNA4yI1pJEQuVxDHJetXNvf0TnVtntdv3pt7S mU+U/5/XbqzbqrrnnllhA7NXoWykRGGrLpAEm0DZSULFWpdAcwcYJsdBbijEwFNKbVOnmHIk3bt mDjlIOgRAXlljw9xu9VS/IB41PuizE X-Received: by 2002:a05:620a:2892:b0:930:771e:e8d0 with SMTP id af79cd13be357-930771ee8femr292906285a.25.1784012773699; Tue, 14 Jul 2026 00:06:13 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-92ee5d69a78sm1390950185a.44.2026.07.14.00.06.13 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 14 Jul 2026 00:06:13 -0700 (PDT) From: David Lee To: Jon Maloy Cc: David Lee , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Richard Alpe , Ying Xue , Dominik 'Disconnect3d' Czarnota , netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org Subject: [PATCH net] tipc: prevent node timer rearm after peer removal Date: Tue, 14 Jul 2026 07:06:09 +0000 Message-ID: <20260714070611.1700456-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" TIPC node deletion removes the node from lookup tables, calls timer_delete_sync(), and drops the timer reference. This stops an already running timer callback, but it does not prevent another racing path from rearming the same timer after deletion has started. Synthetic UDP discovery can race TIPC_NL_PEER_REMOVE and link property updates. When discovery recreates the first link, tipc_node_check_dest() calls mod_timer() and retakes the timer reference. If that happens after tipc_node_delete() has deleted the timer, the orphaned timer can later run after network namespace teardown has freed the per-net TIPC state and broadcast link. Use timer_shutdown_sync() when deleting a node. Shutdown has the same synchronization effect as timer_delete_sync(), and also prevents future rearming through mod_timer(). Fixes: b34040227be7 ("tipc: add peer removal functionality") Signed-off-by: David Lee Assisted-by: Codex:gpt-5.5 --- Trail of Bits has a reproducer for this bug demonstrating Kernel Panic whic= h can be shared further if needed. net/tipc/node.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/tipc/node.c b/net/tipc/node.c index 262b39ecf5f8..5b3ee44347be 100644 --- a/net/tipc/node.c +++ b/net/tipc/node.c @@ -638,7 +638,7 @@ static void tipc_node_delete(struct tipc_node *node) trace_tipc_node_delete(node, true, " "); tipc_node_delete_from_list(node); =20 - timer_delete_sync(&node->timer); + timer_shutdown_sync(&node->timer); tipc_node_put(node); } =20 --=20 2.43.0