aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-06-23 21:46:17 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-29 19:16:40 +0000
commit490e506a1ca8e766340fdea1a72eeea27e006293 (patch)
tree4aafd4672c07f25046910dcf5ad03310027dc860
parent63a8e7bc0412f6d3d113839ed9e83e5c4bf8fd39 (diff)
rack: Reload the TCP stack PCB after reacquiring the inpcb lock
Malicious userspace might switch TCP stacks twice while the inpcb lock is dropped. If it does so, the validation of tp->t_fb might succeed, but the saved pointer to the stack PCB might be invalid. Reload it to avoid this problem, as BBR already does. Approved by: so Security: FreeBSD-SA-26:43.tcp Security: CVE-2026-49422 Reported by: Maik Münch Reviewed by: tuexen Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57791
-rw-r--r--sys/netinet/tcp_stacks/rack.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/sys/netinet/tcp_stacks/rack.c b/sys/netinet/tcp_stacks/rack.c
index 219cf2758ff2..86ea34f46a05 100644
--- a/sys/netinet/tcp_stacks/rack.c
+++ b/sys/netinet/tcp_stacks/rack.c
@@ -24136,6 +24136,7 @@ process_opt:
INP_WUNLOCK(inp);
return (ENOPROTOOPT);
}
+ rack = (struct tcp_rack *)tp->t_fb_ptr;
if (rack->defer_options && (rack->gp_ready == 0) &&
(sopt->sopt_name != TCP_DEFER_OPTIONS) &&
(sopt->sopt_name != TCP_HYBRID_PACING) &&