Skip to content

Fixed with_sealed_socket UAF issue - #106

Open
nding0405 wants to merge 1 commit into
CHERIoT-Platform:mainfrom
nding0405:fix-with-sealed-socket-UAF
Open

Fixed with_sealed_socket UAF issue#106
nding0405 wants to merge 1 commit into
CHERIoT-Platform:mainfrom
nding0405:fix-with-sealed-socket-UAF

Conversation

@nding0405

Copy link
Copy Markdown
Contributor

This PR partially addresses issue #104. It adds an ephemeral claim in with_sealed_socket() to prevent a Use-After-Free when the socket is dereferenced before acquiring its lock. The remaining case mentioned in #104 that needs to be fixed is in network_socket_close(), where we need another ephemeral claim to prevent a Use-After-Free if the lock has already been destroyed during a reset.

@nding0405
nding0405 force-pushed the fix-with-sealed-socket-UAF branch from a53167f to ab2c27f Compare July 22, 2026 23:21
Currently, in the lockless with_sealed_socket, we dereference the
socket to read epoch while not holding the socket lock. That will
lead to UAF bug and trigger network stack crash when another thread
frees the socket. To address this, heap_claim_ephemeral has been
added right before dereferencing the socket. It will return -EINVAL
if the socket is freed by some other threads.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant