aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-06-23 21:46:17 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-30 17:00:21 +0000
commitdf8885512da546e6ba619039625ec43a945b9889 (patch)
tree01b6e0e640ce9be5912965c4db81edf4479d55a6
parent7982ae91a51a1f30b6ad7d12c5eedc4b46a37992 (diff)
rack: Reload the TCP stack PCB after reacquiring the inpcb lock
Malicious userspace might switch TCP stacks twice while the inpcb lock is dropped. If it does so, the validation of tp->t_fb might succeed, but the saved pointer to the stack PCB might be invalid. Reload it to avoid this problem, as BBR already does. Approved by: so Security: FreeBSD-SA-26:43.tcp Security: CVE-2026-49422 Reported by: Maik Münch Reviewed by: tuexen Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57791
-rw-r--r--sys/netinet/tcp_stacks/rack.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/sys/netinet/tcp_stacks/rack.c b/sys/netinet/tcp_stacks/rack.c
index 9b35fbb7797b..41a57eeedfde 100644
--- a/sys/netinet/tcp_stacks/rack.c
+++ b/sys/netinet/tcp_stacks/rack.c
@@ -23936,6 +23936,7 @@ process_opt:
INP_WUNLOCK(inp);
return (ENOPROTOOPT);
}
+ rack = (struct tcp_rack *)tp->t_fb_ptr;
if (rack->defer_options && (rack->gp_ready == 0) &&
(sopt->sopt_name != TCP_DEFER_OPTIONS) &&
(sopt->sopt_name != TCP_HYBRID_PACING) &&