2 Commits
Author SHA1 Message Date
Alex fba975192b tun: fix NULL pointer dereference race in tun_get() (#54)
The tun_get() function has a race condition where tun->dev can become
NULL between checking tun and calling dev_hold(tun->dev).

This occurs when tun_detach_all() runs concurrently:
1. tun_get() calls rcu_dereference(tfile->tun), gets valid tun
2. Another thread calls tun_detach_all() which sets tun->dev to NULL
3. dev_hold(tun->dev) dereferences NULL pointer -> kernel crash

Fix by reading tun->dev into a local variable with READ_ONCE() and
verifying both the pointer and device registration state before
taking the reference.

Crash signature:
  Unable to handle kernel NULL pointer dereference at virtual address 00000004
  PC is at tun_get+0x16/0x22 [tun]
2026-04-08 12:36:08 +02:00
Siyuan f797590b6c Release 202502151445 2025-02-15 18:30:23 +01:00