aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-06-23 21:46:17 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-30 02:32:01 +0000
commit8845978fec035db3a9643d7f36843dfc7c6c68d8 (patch)
tree0c48448e7683f596c3fb0dbbbbb29d64eb9785e4
parentacfff8b35bfe31c53f92cf6ac040afa4a9a0f0ef (diff)
rack: Reload the TCP stack PCB after reacquiring the inpcb lock
Malicious userspace might switch TCP stacks twice while the inpcb lock is dropped. If it does so, the validation of tp->t_fb might succeed, but the saved pointer to the stack PCB might be invalid. Reload it to avoid this problem, as BBR already does. Approved by: so Security: FreeBSD-SA-26:43.tcp Security: CVE-2026-49422 Reported by: Maik Münch Reviewed by: tuexen Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57791
-rw-r--r--sys/netinet/tcp_stacks/rack.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/sys/netinet/tcp_stacks/rack.c b/sys/netinet/tcp_stacks/rack.c
index f90b747cc2e4..3d6734b6874b 100644
--- a/sys/netinet/tcp_stacks/rack.c
+++ b/sys/netinet/tcp_stacks/rack.c
@@ -23934,6 +23934,7 @@ process_opt:
INP_WUNLOCK(inp);
return (ENOPROTOOPT);
}
+ rack = (struct tcp_rack *)tp->t_fb_ptr;
if (rack->defer_options && (rack->gp_ready == 0) &&
(sopt->sopt_name != TCP_DEFER_OPTIONS) &&
(sopt->sopt_name != TCP_HYBRID_PACING) &&