android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ilya Maximets 3415faa1fc net: openvswitch: remove never-working support for setting nsh fields
[ Upstream commit dfe28c4167a9259fc0c372d9f9473e1ac95cff67 ]

The validation of the set(nsh(...)) action is completely wrong.
It runs through the nsh_key_put_from_nlattr() function that is the
same function that validates NSH keys for the flow match and the
push_nsh() action.  However, the set(nsh(...)) has a very different
memory layout.  Nested attributes in there are doubled in size in
case of the masked set().  That makes proper validation impossible.

There is also confusion in the code between the 'masked' flag, that
says that the nested attributes are doubled in size containing both
the value and the mask, and the 'is_mask' that says that the value
we're parsing is the mask.  This is causing kernel crash on trying to
write into mask part of the match with SW_FLOW_KEY_PUT() during
validation, while validate_nsh() doesn't allocate any memory for it:

  BUG: kernel NULL pointer dereference, address: 0000000000000018
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0
  Oops: Oops: 0000 [#1] SMP NOPTI
  CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary)
  RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch]
  Call Trace:
   <TASK>
   validate_nsh+0x60/0x90 [openvswitch]
   validate_set.constprop.0+0x270/0x3c0 [openvswitch]
   __ovs_nla_copy_actions+0x477/0x860 [openvswitch]
   ovs_nla_copy_actions+0x8d/0x100 [openvswitch]
   ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch]
   genl_family_rcv_msg_doit+0xdb/0x130
   genl_family_rcv_msg+0x14b/0x220
   genl_rcv_msg+0x47/0xa0
   netlink_rcv_skb+0x53/0x100
   genl_rcv+0x24/0x40
   netlink_unicast+0x280/0x3b0
   netlink_sendmsg+0x1f7/0x430
   ____sys_sendmsg+0x36b/0x3a0
   ___sys_sendmsg+0x87/0xd0
   __sys_sendmsg+0x6d/0xd0
   do_syscall_64+0x7b/0x2c0
   entry_SYSCALL_64_after_hwframe+0x76/0x7e

The third issue with this process is that while trying to convert
the non-masked set into masked one, validate_set() copies and doubles
the size of the OVS_KEY_ATTR_NSH as if it didn't have any nested
attributes.  It should be copying each nested attribute and doubling
them in size independently.  And the process must be properly reversed
during the conversion back from masked to a non-masked variant during
the flow dump.

In the end, the only two outcomes of trying to use this action are
either validation failure or a kernel crash.  And if somehow someone
manages to install a flow with such an action, it will most definitely
not do what it is supposed to, since all the keys and the masks are
mixed up.

Fixing all the issues is a complex task as it requires re-writing
most of the validation code.

Given that and the fact that this functionality never worked since
introduction, let's just remove it altogether.  It's better to
re-introduce it later with a proper implementation instead of trying
to fix it in stable releases.

Fixes: b2d0f5d5dc ("openvswitch: enable NSH support")
Reported-by: Junvy Yang <zhuque@tencent.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Acked-by: Eelco Chaudron <echaudro@redhat.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20251112112246.95064-1-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:20 +01:00
..
6lowpan
9p net/9p: fix double req put in p9_fd_cancelled 2025-10-29 13:59:54 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: sync VLAN features with lower device 2025-12-03 12:45:15 +01:00
appletalk net: appletalk: Fix use-after-free in AARP proxy probe 2025-08-28 16:21:17 +02:00
atm net: atm: fix memory leak in atm_register_sysfs when device_register fail 2025-09-09 18:43:58 +02:00
ax25 ax25: properly unshare skbs in ax25_kiss_rcv() 2025-09-09 18:43:58 +02:00
batman-adv batman-adv: fix OOB read/write in network-coding decode 2025-09-09 18:43:59 +02:00
bluetooth Bluetooth: L2CAP: export l2cap_chan_hold for modules 2025-12-03 12:45:18 +01:00
bpf
bpfilter bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
bridge bridge: Redirect to backup port when port is administratively down 2025-12-03 12:45:09 +01:00
caif caif: reduce stack size, again 2025-08-28 16:21:19 +02:00
can can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails 2025-10-02 13:34:29 +02:00
ceph
core page_pool: Clamp pool size to max 16K pages 2025-12-03 12:45:14 +01:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa net: dsa: microchip: linearize skb for tail-tagging switches 2025-09-09 18:44:00 +02:00
ethernet
hsr
ieee802154
ife
ipv4 ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe 2025-12-03 12:45:19 +01:00
ipv6 ipv6: np->rxpmtu race annotation 2025-12-03 12:45:13 +01:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 wifi: mac80211: skip rate verification for not captured PSDUs 2025-12-03 12:45:17 +01:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). 2025-06-27 11:02:57 +01:00
ncsi net: ncsi: Fix buffer overflow in fetching version id 2025-08-28 16:21:27 +02:00
netfilter ipvs: Defer ip_vs_ftp unregister during netns cleanup 2025-10-29 13:59:49 +01:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink netlink: avoid infinite retry looping in netlink_unicast() 2025-08-28 16:21:23 +02:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: uart: Set tty->disc_data only in success path 2025-06-27 11:02:51 +01:00
nsh
openvswitch net: openvswitch: remove never-working support for setting nsh fields 2025-12-03 12:45:20 +01:00
packet net/packet: fix a race in packet_set_ring() and packet_notifier() 2025-08-28 16:21:23 +02:00
phonet phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() 2025-08-28 16:21:14 +02:00
psample
qrtr
rds rds: Fix endianness annotation for RDS_MPATH_HASH 2025-12-03 12:45:10 +01:00
rfkill net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer 2025-10-02 13:34:32 +02:00
rose rose: fix dangling neighbour pointers in rose_rt_device_down() 2025-07-17 18:25:00 +02:00
rxrpc rxrpc: Fix oops due to non-existence of prealloc backlog struct 2025-07-17 18:25:02 +02:00
sched net_sched: limit try_bulk_dequeue_skb() batches 2025-12-03 12:45:18 +01:00
sctp sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto 2025-12-03 12:45:17 +01:00
smc
strparser strparser: Fix signed/unsigned mismatch bug 2025-12-03 12:45:19 +01:00
sunrpc xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create 2025-06-27 11:02:58 +01:00
switchdev
tipc tipc: Fix use-after-free in tipc_mon_reinit_self(). 2025-12-03 12:45:17 +01:00
tls tls: don't rely on tx_work during send() 2025-10-29 13:59:57 +01:00
unix
vmw_vsock vsock: Do not allow binding to VMADDR_PORT_ANY 2025-08-28 16:21:23 +02:00
wimax
wireless wifi: cfg80211: fix use-after-free in cmp_bss() 2025-09-09 18:43:56 +02:00
x25
xdp
xfrm xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c