On Wed, Aug 12, 2026 at 08:56:38PM +0200, Jann Horn wrote:
> Some refcount issues are not necessarily associated with memory corruption,
> but REFCOUNT_ADD_UAF suggests that a UAF either just happened or is about
> to happen.
> 
> REFCOUNT_SUB_UAF is also an indicator that reference counting is wrong, and
> suggests (less strongly) that a UAF access might have happened recently.
> 
> In these cases, BUG() is appropriate if CONFIG_BUG_ON_DATA_CORRUPTION is
> set.
> 
> Signed-off-by: Jann Horn <[email protected]>
> ---
> MAINTAINERS specifies no specific maintainer for lib/refcount.c, but it
> does have an entry for include/linux/refcount.h, so I guess I should
> route this patch based on that.
> 
> I decided to send this patch after wondering how exploitable it would be
> to have a refcount_inc() call on an object which has reached refcount 0,
> but is not yet freed because of something like an RCU grace period.
> ---
>  lib/refcount.c | 15 ++++++++++++---
>  1 file changed, 12 insertions(+), 3 deletions(-)
> 
> diff --git a/lib/refcount.c b/lib/refcount.c
> index a207a8f22b3c..c0f0dc5296eb 100644
> --- a/lib/refcount.c
> +++ b/lib/refcount.c
> @@ -10,6 +10,15 @@
>  
>  #define REFCOUNT_WARN(str)   WARN_ONCE(1, "refcount_t: " str ".\n")
>  
> +#ifdef CONFIG_BUG_ON_DATA_CORRUPTION
> +#define REFCOUNT_CORRUPTION(str) ({          \
> +     pr_err("refcount_t: " str ".\n");       \
> +     BUG();                                  \
> +})
> +#else
> +#define REFCOUNT_CORRUPTION(str) REFCOUNT_WARN(str)
> +#endif

Can you use CHECK_DATA_CORRUPTION() here instead of open-coding the BUG()?

Either way:

Acked-by: Will Deacon <[email protected]>

Will

Reply via email to