From: Zihan Xi <[email protected]>

A failed loopback connect() can leave sk_err set on a reusable
AF_VSOCK socket. If userspace then calls listen() on the same socket,
the stale error remains attached to the listener. When a later child
reaches vsock_accept(), the accept path sees listener->sk_err,
rejects the child, and drops only the transient accept reference.

On virtio-based loopback this can leave the rejected child orphaned in
the vsock tables, so repeated iterations leak children and can
ultimately drive the guest into OOM.

Clear sk_err when a socket is transitioned into TCP_LISTEN so an
earlier failed connect() does not poison a new listening socket.

Fixes: d021c344051a ("VSOCK: Introduce VM Sockets")
Cc: [email protected]
Reported-by: Vega <[email protected]>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Zihan Xi <[email protected]>
Signed-off-by: Ren Wei <[email protected]>
---
 net/vmw_vsock/af_vsock.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c
index a06f708f3..3482ba594 100644
--- a/net/vmw_vsock/af_vsock.c
+++ b/net/vmw_vsock/af_vsock.c
@@ -1729,6 +1729,10 @@ static int vsock_listen(struct socket *sock, int backlog)
                goto out;
        }
 
+       /* sk_err might have been set as a result of an earlier
+        * (failed) connect attempt.
+        */
+       sk->sk_err = 0;
        sk->sk_max_ack_backlog = backlog;
        sk->sk_state = TCP_LISTEN;
 
-- 
2.43.0

Reply via email to