[PATCH net] xfrm: Fix skb double-free in xfrm_dev_direct_output()

Sanghyun Park posted 1 patch 2 days, 15 hours ago
net/xfrm/xfrm_output.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
[PATCH net] xfrm: Fix skb double-free in xfrm_dev_direct_output()
Posted by Sanghyun Park 2 days, 15 hours ago
A return value other than 1 from local_out() means that the skb has been
consumed or its ownership was transferred. xfrm_dev_direct_output()
nevertheless frees the skb on this path, causing a double-free when
netfilter drops the packet and invalidating any other owner.

Return the local_out() result directly, matching the ownership handling
in xfrm_output_resume().

Fixes: 5eddd76ec2fd ("xfrm: fix tunnel mode TX datapath in packet offload mode")
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
---
 net/xfrm/xfrm_output.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/net/xfrm/xfrm_output.c b/net/xfrm/xfrm_output.c
index cc35c2fcbbe09..e305ba32e356b 100644
--- a/net/xfrm/xfrm_output.c
+++ b/net/xfrm/xfrm_output.c
@@ -636,10 +636,8 @@ static int xfrm_dev_direct_output(struct sock *sk, struct xfrm_state *x,
 	nf_reset_ct(skb);
 
 	err = skb_dst(skb)->ops->local_out(net, sk, skb);
-	if (unlikely(err != 1)) {
-		kfree_skb(skb);
+	if (unlikely(err != 1))
 		return err;
-	}
 
 	/* In transport mode, network destination is
 	 * directly reachable, while in tunnel mode,
Re: [PATCH net] xfrm: Fix skb double-free in xfrm_dev_direct_output()
Posted by Leon Romanovsky 2 days, 14 hours ago
On Wed, Jul 22, 2026 at 04:28:38PM +0900, Sanghyun Park wrote:
> A return value other than 1 from local_out() means that the skb has been
> consumed or its ownership was transferred. xfrm_dev_direct_output()
> nevertheless frees the skb on this path, causing a double-free when
> netfilter drops the packet and invalidating any other owner.
> 
> Return the local_out() result directly, matching the ownership handling
> in xfrm_output_resume().
> 
> Fixes: 5eddd76ec2fd ("xfrm: fix tunnel mode TX datapath in packet offload mode")
> Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
> ---
>  net/xfrm/xfrm_output.c | 4 +---
>  1 file changed, 1 insertion(+), 3 deletions(-)
> 

Thanks,
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>