This is a note to let you know that I've just added the patch titled tcp: clear saved_syn in tcp_disconnect() to the 4.10-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: tcp-clear-saved_syn-in-tcp_disconnect.patch and it can be found in the queue-4.10 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From foo@baz Sat Apr 29 08:22:40 CEST 2017 From: Eric Dumazet <edumazet@xxxxxxxxxx> Date: Sat, 8 Apr 2017 08:07:33 -0700 Subject: tcp: clear saved_syn in tcp_disconnect() From: Eric Dumazet <edumazet@xxxxxxxxxx> [ Upstream commit 17c3060b1701fc69daedb4c90be6325d3d9fca8e ] In the (very unlikely) case a passive socket becomes a listener, we do not want to duplicate its saved SYN headers. This would lead to double frees, use after free, and please hackers and various fuzzers Tested: 0 socket(..., SOCK_STREAM, IPPROTO_TCP) = 3 +0 setsockopt(3, IPPROTO_TCP, TCP_SAVE_SYN, [1], 4) = 0 +0 fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 +0 bind(3, ..., ...) = 0 +0 listen(3, 5) = 0 +0 < S 0:0(0) win 32972 <mss 1460,nop,wscale 7> +0 > S. 0:0(0) ack 1 <...> +.1 < . 1:1(0) ack 1 win 257 +0 accept(3, ..., ...) = 4 +0 connect(4, AF_UNSPEC, ...) = 0 +0 close(3) = 0 +0 bind(4, ..., ...) = 0 +0 listen(4, 5) = 0 +0 < S 0:0(0) win 32972 <mss 1460,nop,wscale 7> +0 > S. 0:0(0) ack 1 <...> +.1 < . 1:1(0) ack 1 win 257 Fixes: cd8ae85299d5 ("tcp: provide SYN headers for passive connections") Signed-off-by: Eric Dumazet <edumazet@xxxxxxxxxx> Signed-off-by: David S. Miller <davem@xxxxxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- net/ipv4/tcp.c | 1 + 1 file changed, 1 insertion(+) --- a/net/ipv4/tcp.c +++ b/net/ipv4/tcp.c @@ -2301,6 +2301,7 @@ int tcp_disconnect(struct sock *sk, int tcp_init_send_head(sk); memset(&tp->rx_opt, 0, sizeof(tp->rx_opt)); __sk_dst_reset(sk); + tcp_saved_syn_free(tp); WARN_ON(inet->inet_num && !icsk->icsk_bind_hash); Patches currently in stable-queue which might be from edumazet@xxxxxxxxxx are queue-4.10/ping-implement-proper-locking.patch queue-4.10/tcp-mark-skbs-with-scm_timestamping_opt_stats.patch queue-4.10/tcp-clear-saved_syn-in-tcp_disconnect.patch queue-4.10/net-ipv6-regenerate-host-route-if-moved-to-gc-list.patch queue-4.10/secure_seq-downgrade-to-per-host-timestamp-offsets.patch queue-4.10/net-packet-fix-overflow-in-check-for-tp_frame_nr.patch queue-4.10/net-packet-fix-overflow-in-check-for-tp_reserve.patch queue-4.10/net-neigh-guard-against-null-solicit-method.patch queue-4.10/tcp-fix-scm_timestamping_opt_stats-for-normal-skbs.patch queue-4.10/tcp-memset-ca_priv-data-to-0-properly.patch