android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kuniyuki Iwashima 106e457953 tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().
commit e8c526f2bdf1845bedaf6a478816a3d06fa78b8f upstream.

Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler().

  """
  We are seeing a use-after-free from a bpf prog attached to
  trace_tcp_retransmit_synack. The program passes the req->sk to the
  bpf_sk_storage_get_tracing kernel helper which does check for null
  before using it.
  """

The commit 83fccfc394 ("inet: fix potential deadlock in
reqsk_queue_unlink()") added timer_pending() in reqsk_queue_unlink() not
to call del_timer_sync() from reqsk_timer_handler(), but it introduced a
small race window.

Before the timer is called, expire_timers() calls detach_timer(timer, true)
to clear timer->entry.pprev and marks it as not pending.

If reqsk_queue_unlink() checks timer_pending() just after expire_timers()
calls detach_timer(), TCP will miss del_timer_sync(); the reqsk timer will
continue running and send multiple SYN+ACKs until it expires.

The reported UAF could happen if req->sk is close()d earlier than the timer
expiration, which is 63s by default.

The scenario would be

  1. inet_csk_complete_hashdance() calls inet_csk_reqsk_queue_drop(),
     but del_timer_sync() is missed

  2. reqsk timer is executed and scheduled again

  3. req->sk is accept()ed and reqsk_put() decrements rsk_refcnt, but
     reqsk timer still has another one, and inet_csk_accept() does not
     clear req->sk for non-TFO sockets

  4. sk is close()d

  5. reqsk timer is executed again, and BPF touches req->sk

Let's not use timer_pending() by passing the caller context to
__inet_csk_reqsk_queue_drop().

Note that reqsk timer is pinned, so the issue does not happen in most
use cases. [1]

[0]
BUG: KFENCE: use-after-free read in bpf_sk_storage_get_tracing+0x2e/0x1b0

Use-after-free read at 0x00000000a891fb3a (in kfence-#1):
bpf_sk_storage_get_tracing+0x2e/0x1b0
bpf_prog_5ea3e95db6da0438_tcp_retransmit_synack+0x1d20/0x1dda
bpf_trace_run2+0x4c/0xc0
tcp_rtx_synack+0xf9/0x100
reqsk_timer_handler+0xda/0x3d0
run_timer_softirq+0x292/0x8a0
irq_exit_rcu+0xf5/0x320
sysvec_apic_timer_interrupt+0x6d/0x80
asm_sysvec_apic_timer_interrupt+0x16/0x20
intel_idle_irq+0x5a/0xa0
cpuidle_enter_state+0x94/0x273
cpu_startup_entry+0x15e/0x260
start_secondary+0x8a/0x90
secondary_startup_64_no_verify+0xfa/0xfb

kfence-#1: 0x00000000a72cc7b6-0x00000000d97616d9, size=2376, cache=TCPv6

allocated by task 0 on cpu 9 at 260507.901592s:
sk_prot_alloc+0x35/0x140
sk_clone_lock+0x1f/0x3f0
inet_csk_clone_lock+0x15/0x160
tcp_create_openreq_child+0x1f/0x410
tcp_v6_syn_recv_sock+0x1da/0x700
tcp_check_req+0x1fb/0x510
tcp_v6_rcv+0x98b/0x1420
ipv6_list_rcv+0x2258/0x26e0
napi_complete_done+0x5b1/0x2990
mlx5e_napi_poll+0x2ae/0x8d0
net_rx_action+0x13e/0x590
irq_exit_rcu+0xf5/0x320
common_interrupt+0x80/0x90
asm_common_interrupt+0x22/0x40
cpuidle_enter_state+0xfb/0x273
cpu_startup_entry+0x15e/0x260
start_secondary+0x8a/0x90
secondary_startup_64_no_verify+0xfa/0xfb

freed by task 0 on cpu 9 at 260507.927527s:
rcu_core_si+0x4ff/0xf10
irq_exit_rcu+0xf5/0x320
sysvec_apic_timer_interrupt+0x6d/0x80
asm_sysvec_apic_timer_interrupt+0x16/0x20
cpuidle_enter_state+0xfb/0x273
cpu_startup_entry+0x15e/0x260
start_secondary+0x8a/0x90
secondary_startup_64_no_verify+0xfa/0xfb

Fixes: 83fccfc394 ("inet: fix potential deadlock in reqsk_queue_unlink()")
Reported-by: Martin KaFai Lau <martin.lau@kernel.org>
Closes: https://lore.kernel.org/netdev/eb6684d0-ffd9-4bdc-9196-33f690c25824@linux.dev/
Link: https://lore.kernel.org/netdev/b55e2ca0-42f2-4b7c-b445-6ffd87ca74a0@linux.dev/ [1]
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Martin KaFai Lau <martin.lau@kernel.org>
Link: https://patch.msgid.link/20241014223312.4254-1-kuniyu@amazon.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[Resolved conflicts due to context difference]
Signed-off-by: Nathan Gao <zcgao@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-05-02 07:39:22 +02:00
..
6lowpan
9p 9p/xen: fix release of IRQ 2024-12-14 19:44:41 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: don't propagate flags on open 2025-05-02 07:39:11 +02:00
appletalk
atm atm: Fix NULL pointer dereference 2025-04-10 14:29:38 +02:00
ax25
batman-adv batman-adv: Ignore own maximum aggregation size during RX 2025-04-10 14:29:38 +02:00
bluetooth Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for invalid address 2025-05-02 07:39:19 +02:00
bpf
bpfilter
bridge netfilter: Replace zero-length array with flexible-array member 2025-01-09 13:23:35 +01:00
caif
can can: statistics: use atomic access in hot path 2025-04-10 14:29:42 +02:00
ceph
core bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags 2025-05-02 07:39:13 +02:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa
ethernet
hsr
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife
ipv4 tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). 2025-05-02 07:39:22 +02:00
ipv6 ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS 2025-04-10 14:29:43 +02:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc llc: do not use skb_get() before dev_queue_xmit() 2025-03-13 12:43:29 +01:00
mac80211 Revert "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()" 2025-05-02 07:39:19 +02:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls
ncsi net/ncsi: wait for the last response to Deselect Package before configuring channel 2025-03-13 12:43:11 +01:00
netfilter netfilter: nft_exthdr: fix offset with ipv4_find_option() 2025-04-10 14:29:35 +02:00
netlabel
netlink
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: Add bounds checking in nci_hci_create_pipe() 2025-03-13 12:43:11 +01:00
nsh
openvswitch net: openvswitch: fix nested key length validation in the set() action 2025-05-02 07:39:19 +02:00
packet af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK 2025-01-09 13:23:35 +01:00
phonet
psample
qrtr
rds
rfkill
rose net: rose: lock the socket in rose_bind() 2025-03-13 12:43:06 +01:00
rxrpc
sched net_sched: skbprio: Remove overly strict queue assertions 2025-04-10 14:29:43 +02:00
sctp sctp: detect and prevent references to a freed transport in sendmsg 2025-05-02 07:39:16 +02:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser
sunrpc sunrpc: suppress warnings for unused procfs functions 2025-03-13 12:43:24 +01:00
switchdev
tipc tipc: fix memory leak in tipc_link_xmit 2025-05-02 07:39:08 +02:00
tls tls: Fix tls_sw_sendmsg error handling 2025-02-01 18:18:45 +01:00
unix
vmw_vsock vsock: avoid timeout during connect() if the socket is closing 2025-04-10 14:29:43 +02:00
wimax
wireless wifi: nl80211: reject cooked mode if it is set along with other flags 2025-03-13 12:43:28 +01:00
x25
xdp
xfrm xfrm_output: Force software GSO only in tunnel mode 2025-04-10 14:29:37 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c