Eric Dumazet
22d95b5449
net_sched: add __rcu annotation to netdev->qdisc
commit 5891cd5ec46c2c2eb6427cb54d214b149635dd0e upstream.
syzbot found a data-race [1] which lead me to add __rcu
annotations to netdev->qdisc, and proper accessors
to get LOCKDEP support.
[1]
BUG: KCSAN: data-race in dev_activate / qdisc_lookup_rcu
write to 0xffff888168ad6410 of 8 bytes by task 13559 on cpu 1:
attach_default_qdiscs net/sched/sch_generic.c:1167 [inline]
dev_activate+0x2ed/0x8f0 net/sched/sch_generic.c:1221
__dev_open+0x2e9/0x3a0 net/core/dev.c:1416
__dev_change_flags+0x167/0x3f0 net/core/dev.c:8139
rtnl_configure_link+0xc2/0x150 net/core/rtnetlink.c:3150
__rtnl_newlink net/core/rtnetlink.c:3489 [inline]
rtnl_newlink+0xf4d/0x13e0 net/core/rtnetlink.c:3529
rtnetlink_rcv_msg+0x745/0x7e0 net/core/rtnetlink.c:5594
netlink_rcv_skb+0x14e/0x250 net/netlink/af_netlink.c:2494
rtnetlink_rcv+0x18/0x20 net/core/rtnetlink.c:5612
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x602/0x6d0 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x728/0x850 net/netlink/af_netlink.c:1919
sock_sendmsg_nosec net/socket.c:705 [inline]
sock_sendmsg net/socket.c:725 [inline]
____sys_sendmsg+0x39a/0x510 net/socket.c:2413
___sys_sendmsg net/socket.c:2467 [inline]
__sys_sendmsg+0x195/0x230 net/socket.c:2496
__do_sys_sendmsg net/socket.c:2505 [inline]
__se_sys_sendmsg net/socket.c:2503 [inline]
__x64_sys_sendmsg+0x42/0x50 net/socket.c:2503
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
read to 0xffff888168ad6410 of 8 bytes by task 13560 on cpu 0:
qdisc_lookup_rcu+0x30/0x2e0 net/sched/sch_api.c:323
__tcf_qdisc_find+0x74/0x3a0 net/sched/cls_api.c:1050
tc_del_tfilter+0x1c7/0x1350 net/sched/cls_api.c:2211
rtnetlink_rcv_msg+0x5ba/0x7e0 net/core/rtnetlink.c:5585
netlink_rcv_skb+0x14e/0x250 net/netlink/af_netlink.c:2494
rtnetlink_rcv+0x18/0x20 net/core/rtnetlink.c:5612
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x602/0x6d0 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x728/0x850 net/netlink/af_netlink.c:1919
sock_sendmsg_nosec net/socket.c:705 [inline]
sock_sendmsg net/socket.c:725 [inline]
____sys_sendmsg+0x39a/0x510 net/socket.c:2413
___sys_sendmsg net/socket.c:2467 [inline]
__sys_sendmsg+0x195/0x230 net/socket.c:2496
__do_sys_sendmsg net/socket.c:2505 [inline]
__se_sys_sendmsg net/socket.c:2503 [inline]
__x64_sys_sendmsg+0x42/0x50 net/socket.c:2503
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
value changed: 0xffffffff85dee080 -> 0xffff88815d96ec00
Reported by Kernel Concurrency Sanitizer on:
CPU: 0 PID: 13560 Comm: syz-executor.2 Not tainted 5.17.0-rc3-syzkaller-00116-gf1baf68e1383-dirty #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Fixes: 470502de5b ("net: sched: unlock rules update API")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Vlad Buslov <vladbu@mellanox.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Cong Wang <xiyou.wangcong@gmail.com>
Cc: Jiri Pirko <jiri@resnulli.us>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Zubin Mithra <zsm@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2023-04-05 11:16:46 +02:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p/rdma: unmap receive dma buffer in rdma_request()/post_recv()
|
2023-03-11 16:44:12 +01:00 |
|
802
|
mrp: introduce active flags to prevent UAF when applicant uninit
|
2023-01-18 11:41:37 +01:00 |
|
8021q
|
|
|
|
appletalk
|
|
|
|
atm
|
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
|
2023-03-11 16:43:42 +01:00 |
|
ax25
|
|
|
|
batman-adv
|
|
|
|
bluetooth
|
Bluetooth: hci_sock: purge socket queues in the destruct() callback
|
2023-03-11 16:44:16 +01:00 |
|
bpf
|
bpf: Move skb->len == 0 checks into __bpf_redirect
|
2023-01-18 11:41:04 +01:00 |
|
bpfilter
|
|
|
|
bridge
|
netfilter: br_netfilter: disable sabotage_in hook after first suppression
|
2023-02-22 12:50:24 +01:00 |
|
caif
|
net: caif: Fix use-after-free in cfusbl_device_notify()
|
2023-03-17 08:32:51 +01:00 |
|
can
|
can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in vfs_write
|
2023-04-05 11:16:44 +02:00 |
|
ceph
|
|
|
|
core
|
net_sched: add __rcu annotation to netdev->qdisc
|
2023-04-05 11:16:46 +02:00 |
|
dcb
|
|
|
|
dccp
|
dccp/tcp: Avoid negative sk_forward_alloc by ipv6_pinfo.pktoptions.
|
2023-02-22 12:50:40 +01:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: ksz: Check return value
|
2022-12-14 11:30:45 +01:00 |
|
ethernet
|
|
|
|
hsr
|
hsr: Avoid double remove of a node.
|
2023-01-18 11:41:09 +01:00 |
|
ieee802154
|
net: ieee802154: fix error return code in dgram_bind()
|
2022-11-03 23:56:54 +09:00 |
|
ife
|
|
|
|
ipv4
|
erspan: do not use skb_mac_header() in ndo_start_xmit()
|
2023-04-05 11:16:38 +02:00 |
|
ipv6
|
erspan: do not use skb_mac_header() in ndo_start_xmit()
|
2023-04-05 11:16:38 +02:00 |
|
iucv
|
net/iucv: Fix size of interrupt data
|
2023-03-22 13:28:06 +01:00 |
|
kcm
|
kcm: close race conditions on sk_receive_queue
|
2022-11-25 17:42:21 +01:00 |
|
key
|
af_key: Fix send_acquire race with pfkey_register
|
2022-12-08 11:22:57 +01:00 |
|
l2tp
|
l2tp: Don't sleep and disable BH under writer-side sk_callback_lock
|
2023-02-06 07:52:38 +01:00 |
|
l3mdev
|
|
|
|
lapb
|
|
|
|
llc
|
|
|
|
mac80211
|
wifi: mac80211: fix qos on mesh interfaces
|
2023-04-05 11:16:41 +02:00 |
|
mac802154
|
mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()
|
2022-12-14 11:30:45 +01:00 |
|
mpls
|
net: mpls: fix stale pointer if allocation fails during device rename
|
2023-02-22 12:50:41 +01:00 |
|
ncsi
|
|
|
|
netfilter
|
netfilter: nft_redir: correct value of inet type .maxattrs
|
2023-03-22 13:28:04 +01:00 |
|
netlabel
|
|
|
|
netlink
|
netlink: annotate data races around sk_state
|
2023-02-06 07:52:45 +01:00 |
|
netrom
|
netrom: Fix use-after-free caused by accept on already connected socket
|
2023-02-22 12:50:24 +01:00 |
|
nfc
|
nfc: change order inside nfc_se_io error path
|
2023-03-17 08:32:48 +01:00 |
|
nsh
|
|
|
|
openvswitch
|
net: openvswitch: fix flow memory leak in ovs_flow_cmd_new
|
2023-02-22 12:50:25 +01:00 |
|
packet
|
net/af_packet: make sure to pull mac header
|
2023-01-18 11:41:45 +01:00 |
|
phonet
|
|
|
|
psample
|
|
|
|
qrtr
|
|
|
|
rds
|
rds: rds_rm_zerocopy_callback() correct order for list_add_tail()
|
2023-03-11 16:43:41 +01:00 |
|
rfkill
|
|
|
|
rose
|
net/rose: Fix to not accept on connected socket
|
2023-02-22 12:50:34 +01:00 |
|
rxrpc
|
rxrpc: Fix missing unlock in rxrpc_do_sendmsg()
|
2023-01-18 11:41:33 +01:00 |
|
sched
|
net_sched: add __rcu annotation to netdev->qdisc
|
2023-04-05 11:16:46 +02:00 |
|
sctp
|
sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop
|
2023-03-11 16:44:11 +01:00 |
|
smc
|
net/smc: fix fallback failed while sendmsg with fastopen
|
2023-03-17 08:32:51 +01:00 |
|
strparser
|
|
|
|
sunrpc
|
xprtrdma: Fix regbuf data not freed in rpcrdma_req_create()
|
2023-02-22 12:50:29 +01:00 |
|
switchdev
|
|
|
|
tipc
|
tipc: call tipc_lxc_xmit without holding node_read_lock
|
2023-01-18 11:42:06 +01:00 |
|
tls
|
net: tls: fix possible race condition between do_tls_getsockopt_conf() and do_tls_setsockopt_conf()
|
2023-04-05 11:16:36 +02:00 |
|
unix
|
af_unix: Get user_ns from in_skb in unix_diag_get_exact().
|
2022-12-14 11:30:44 +01:00 |
|
vmw_vsock
|
net: vmw_vsock: vmci: Check memcpy_from_msg()
|
2023-01-18 11:41:13 +01:00 |
|
wimax
|
|
|
|
wireless
|
wifi: cfg80211: Partial revert "wifi: cfg80211: Fix use after free for wext"
|
2023-03-13 10:18:25 +01:00 |
|
x25
|
net/x25: Fix to not accept on connected socket
|
2023-02-22 12:50:26 +01:00 |
|
xdp
|
|
|
|
xfrm
|
xfrm: Allow transport-mode states with AF_UNSPEC selector
|
2023-03-22 13:28:03 +01:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
net: Fix a data-race around sysctl_somaxconn.
|
2022-09-05 10:27:42 +02:00 |
|
sysctl_net.c
|
|
|