Skip to content

Fixed with_sealed_socket UAF issue - #106

Open
nding0405 wants to merge 2 commits into
CHERIoT-Platform:mainfrom
nding0405:fix-with-sealed-socket-UAF
Open

Fixed with_sealed_socket UAF issue#106
nding0405 wants to merge 2 commits into
CHERIoT-Platform:mainfrom
nding0405:fix-with-sealed-socket-UAF

Conversation

@nding0405

Copy link
Copy Markdown
Contributor

This PR partially addresses issue #104. It adds an ephemeral claim in with_sealed_socket() to prevent a Use-After-Free when the socket is dereferenced before acquiring its lock. The remaining case mentioned in #104 that needs to be fixed is in network_socket_close(), where we need another ephemeral claim to prevent a Use-After-Free if the lock has already been destroyed during a reset.

@nding0405
nding0405 force-pushed the fix-with-sealed-socket-UAF branch 2 times, most recently from ab2c27f to cf29fd7 Compare July 22, 2026 23:27
Comment thread lib/tcpip/network_wrapper.cc Outdated
Comment on lines +121 to +128
Timeout unlimited{UnlimitedTimeout};
/**
* We are not holding the socket lock here, but still doing
* deference of the socket, which can lead to an UAF error.
* To address this, we use ephemeral call before dereferencing
* the socket.
*/
int result = heap_claim_ephemeral(&unlimited, socket, nullptr);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The idiomatic way of writing this is:

int result = heap_claim_ephemeral(TimeoutWaitForever, socket, nullptr);

That said, I'm not entirely comfortable having a thing with an unlimited timeout inside APIs that all take a timeout. We should be propagating that down.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we change the signature of the lockless with_sealed_socket? It currently doesn't take the timeout argument.

Currently, in the lockless with_sealed_socket, we dereference the
socket to read epoch while not holding the socket lock. That will
lead to UAF bug and trigger network stack crash when another thread
frees the socket. To address this, heap_claim_ephemeral has been
added right before dereferencing the socket. It will return -EINVAL
if the socket is freed by some other threads.
@nding0405
nding0405 force-pushed the fix-with-sealed-socket-UAF branch from 86ef274 to e106ebd Compare August 9, 2026 00:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants