No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Chuang Wang 69d35c1216 ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
commit ac1499fcd40fe06479e9b933347b837ccabc2a40 upstream.

The sit driver's packet transmission path calls: sit_tunnel_xmit() ->
update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called
to delete entries exceeding FNHE_RECLAIM_DEPTH+random.

The race window is between fnhe_remove_oldest() selecting fnheX for
deletion and the subsequent kfree_rcu(). During this time, the
concurrent path's __mkroute_output() -> find_exception() can fetch the
soon-to-be-deleted fnheX, and rt_bind_exception() then binds it with a
new dst using a dst_hold(). When the original fnheX is freed via RCU,
the dst reference remains permanently leaked.

CPU 0                             CPU 1
__mkroute_output()
  find_exception() [fnheX]
                                  update_or_create_fnhe()
                                    fnhe_remove_oldest() [fnheX]
  rt_bind_exception() [bind dst]
                                  RCU callback [fnheX freed, dst leak]

This issue manifests as a device reference count leak and a warning in
dmesg when unregistering the net device:

  unregister_netdevice: waiting for sitX to become free. Usage count = N

Ido Schimmel provided the simple test validation method [1].

The fix clears 'oldest->fnhe_daddr' before calling fnhe_flush_routes().
Since rt_bind_exception() checks this field, setting it to zero prevents
the stale fnhe from being reused and bound to a new dst just before it
is freed.

[1]
ip netns add ns1
ip -n ns1 link set dev lo up
ip -n ns1 address add 192.0.2.1/32 dev lo
ip -n ns1 link add name dummy1 up type dummy
ip -n ns1 route add 192.0.2.2/32 dev dummy1
ip -n ns1 link add name gretap1 up arp off type gretap \
    local 192.0.2.1 remote 192.0.2.2
ip -n ns1 route add 198.51.0.0/16 dev gretap1
taskset -c 0 ip netns exec ns1 mausezahn gretap1 \
    -A 198.51.100.1 -B 198.51.0.0/16 -t udp -p 1000 -c 0 -q &
taskset -c 2 ip netns exec ns1 mausezahn gretap1 \
    -A 198.51.100.1 -B 198.51.0.0/16 -t udp -p 1000 -c 0 -q &
sleep 10
ip netns pids ns1 | xargs kill
ip netns del ns1

Cc: stable@vger.kernel.org
Fixes: 67d6d681e15b ("ipv4: make exception cache less predictible")
Signed-off-by: Chuang Wang <nashuiliang@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251111064328.24440-1-nashuiliang@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-12-03 12:45:19 +01:00
arch sparc/module: Add R_SPARC_UA64 relocation handling 2025-12-03 12:45:13 +01:00
block block: use int to store blk_stack_limits() return value 2025-10-29 13:59:46 +01:00
certs
crypto crypto: essiv - Check ssize for decryption and in-place encryption 2025-10-29 13:59:52 +01:00
Documentation arm64: errata: Apply workarounds for Neoverse-V3AE 2025-10-29 14:00:00 +01:00
drivers drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE 2025-12-03 12:45:18 +01:00
fs NFS4: Fix state renewals missing after boot 2025-12-03 12:45:16 +01:00
include mm/ksm: fix flag-dropping behavior in ksm_madvise 2025-12-03 12:45:18 +01:00
init bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
ipc
kernel gcov: add support for GCC 15 2025-12-03 12:45:19 +01:00
lib lib/genalloc: fix device leak in of_gen_pool_get() 2025-10-29 13:59:53 +01:00
LICENSES
mm mm: hugetlb: avoid soft lockup when mprotect to large memory area 2025-10-29 13:59:50 +01:00
net ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe 2025-12-03 12:45:19 +01:00
samples samples: mei: Fix building on musl libc 2025-08-28 16:21:19 +02:00
scripts randstruct: gcc-plugin: Fix attribute addition 2025-09-09 18:44:01 +02:00
security KEYS: trusted_tpm1: Compare HMAC values in constant time 2025-10-29 14:00:01 +01:00
sound ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd 2025-12-03 12:45:18 +01:00
tools selftests/Makefile: include $(INSTALL_DEP_TARGETS) in clean target to clean net/lib dependency 2025-12-03 12:45:12 +01:00
usr kbuild: hdrcheck: fix cross build with clang 2025-07-17 18:24:51 +02:00
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.301 2025-10-29 14:00:02 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.