aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-06-23 21:46:17 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-29 19:17:30 +0000
commit800acf75eb80d299fd8ba1e151050da58d481232 (patch)
tree1e2471fd2343ba654bb766844535bffc52ee6164
parent9a6bccc57c68b7bd6fed50720d7a4aa1a4ef9d6c (diff)
rack: Reload the TCP stack PCB after reacquiring the inpcb lock
Malicious userspace might switch TCP stacks twice while the inpcb lock is dropped. If it does so, the validation of tp->t_fb might succeed, but the saved pointer to the stack PCB might be invalid. Reload it to avoid this problem, as BBR already does. Approved by: so Security: FreeBSD-SA-26:43.tcp Security: CVE-2026-49422 Reported by: Maik Münch Reviewed by: tuexen Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57791
-rw-r--r--sys/netinet/tcp_stacks/rack.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/sys/netinet/tcp_stacks/rack.c b/sys/netinet/tcp_stacks/rack.c
index 9b35fbb7797b..41a57eeedfde 100644
--- a/sys/netinet/tcp_stacks/rack.c
+++ b/sys/netinet/tcp_stacks/rack.c
@@ -23936,6 +23936,7 @@ process_opt:
INP_WUNLOCK(inp);
return (ENOPROTOOPT);
}
+ rack = (struct tcp_rack *)tp->t_fb_ptr;
if (rack->defer_options && (rack->gp_ready == 0) &&
(sopt->sopt_name != TCP_DEFER_OPTIONS) &&
(sopt->sopt_name != TCP_HYBRID_PACING) &&