android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kohei Enju 94e0918e39 rose: fix dangling neighbour pointers in rose_rt_device_down()
[ Upstream commit 34a500caf48c47d5171f4aa1f237da39b07c6157 ]

There are two bugs in rose_rt_device_down() that can cause
use-after-free:

1. The loop bound `t->count` is modified within the loop, which can
   cause the loop to terminate early and miss some entries.

2. When removing an entry from the neighbour array, the subsequent entries
   are moved up to fill the gap, but the loop index `i` is still
   incremented, causing the next entry to be skipped.

For example, if a node has three neighbours (A, A, B) with count=3 and A
is being removed, the second A is not checked.

    i=0: (A, A, B) -> (A, B) with count=2
          ^ checked
    i=1: (A, B)    -> (A, B) with count=2
             ^ checked (B, not A!)
    i=2: (doesn't occur because i < count is false)

This leaves the second A in the array with count=2, but the rose_neigh
structure has been freed. Code that accesses these entries assumes that
the first `count` entries are valid pointers, causing a use-after-free
when it accesses the dangling pointer.

Fix both issues by iterating over the array in reverse order with a fixed
loop bound. This ensures that all entries are examined and that the removal
of an entry doesn't affect subsequent iterations.

Reported-by: syzbot+e04e2c007ba2c80476cb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e04e2c007ba2c80476cb
Tested-by: syzbot+e04e2c007ba2c80476cb@syzkaller.appspotmail.com
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Kohei Enju <enjuk@amazon.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250629030833.6680-1-enjuk@amazon.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:00 +02:00
..
6lowpan
9p 9p/xen: fix release of IRQ 2024-12-14 19:44:41 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: don't propagate flags on open 2025-05-02 07:39:11 +02:00
appletalk
atm atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). 2025-07-17 18:24:54 +02:00
ax25
batman-adv batman-adv: Ignore own maximum aggregation size during RX 2025-04-10 14:29:38 +02:00
bluetooth Bluetooth: L2CAP: Fix L2CAP MTU negotiation 2025-07-17 18:24:54 +02:00
bpf
bpfilter bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
bridge netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it 2025-06-27 11:02:46 +01:00
caif
can can: bcm: add missing rcu read protection for procfs content 2025-06-04 14:32:35 +02:00
ceph
core sock: Correct error checking condition for (assign|release)_proto_idx() 2025-06-27 11:02:55 +01:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa
ethernet
hsr
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife
ipv4 tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior 2025-06-27 11:02:57 +01:00
ipv6 calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). 2025-06-27 11:02:57 +01:00
iucv s390/iucv: fix receive buffer virtual vs physical address confusion 2024-09-04 13:14:57 +02:00
kcm kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
key
l2tp genetlink: hold RCU in genlmsg_mcast() 2024-11-08 16:20:50 +01:00
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 wifi: mac80211: drop invalid source address OCB frames 2025-07-17 18:24:57 +02:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). 2025-06-27 11:02:57 +01:00
ncsi net: ncsi: Fix GCPS 64-bit member variables 2025-06-27 11:02:46 +01:00
netfilter netfilter: nft_socket: fix sk refcount leaks 2025-06-27 11:02:44 +01:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink netlink: terminate outstanding dump on socket close 2024-12-14 19:44:18 +01:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: uart: Set tty->disc_data only in success path 2025-06-27 11:02:51 +01:00
nsh
openvswitch openvswitch: Fix unsafe attribute parsing in output_userspace() 2025-06-04 14:32:29 +02:00
packet af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK 2025-01-09 13:23:35 +01:00
phonet
psample
qrtr net: qrtr: Update packets cloning when broadcasting 2024-11-08 16:20:33 +01:00
rds net:rds: Fix possible deadlock in rds_message_put 2024-09-04 13:15:03 +02:00
rfkill net: rfkill: gpio: Add check for clk_enable() 2024-12-14 19:44:27 +01:00
rose rose: fix dangling neighbour pointers in rose_rt_device_down() 2025-07-17 18:25:00 +02:00
rxrpc
sched net/sched: Always pass notifications when child class becomes empty 2025-07-17 18:24:57 +02:00
sctp sctp: Do not wake readers in __sctp_write_space() 2025-06-27 11:02:54 +01:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser
sunrpc xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create 2025-06-27 11:02:58 +01:00
switchdev
tipc tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer 2025-06-27 11:02:57 +01:00
tls ktls, sockmap: Fix missing uncharge operation 2025-06-27 11:02:46 +01:00
unix af_unix: Remove put_pid()/put_cred() in copy_peercred(). 2024-09-12 11:03:52 +02:00
vmw_vsock vsock/vmci: Clear the vmci transport packet properly when initializing it 2025-07-17 18:24:55 +02:00
wimax
wireless wifi: nl80211: reject cooked mode if it is set along with other flags 2025-03-13 12:43:28 +01:00
x25
xdp
xfrm xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c