Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 15 Dec 2025 02:58:34 +0000
From:      bugzilla-noreply@freebsd.org
To:        net@FreeBSD.org
Subject:   [Bug 289017] [lagg] A time-of-check to time-of-use (TOCTOU) race exists in the Link Aggregation (LAGG) network subsystem
Message-ID:  <bug-289017-7501-iKF4PvSKZ2@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-289017-7501@https.bugs.freebsd.org/bugzilla/>
References:  <bug-289017-7501@https.bugs.freebsd.org/bugzilla/>

index | next in thread | previous in thread | raw e-mail

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289017

--- Comment #10 from Gui-Dong Han <hanguidong02@gmail.com> ---
(In reply to Gui-Dong Han from comment #7)

Given that the transmit path can continue into the protocol's start function
after lagg_proto_detach has executed (as evidenced by the crash above), and
considering that detach explicitly frees protocol resources, I believe
triggering a Use-After-Free (UAF) scenario is also highly probable with the
specific timing.

-- 
You are receiving this mail because:
You are the assignee for the bug.

help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-289017-7501-iKF4PvSKZ2>