android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kuniyuki Iwashima 2919297b18 mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
[ Upstream commit 6dbb0d97c5096072c78a6abffe393584e57ae945 ]

As syzbot reported [0], mpls_route_input_rcu() can be called
from mpls_getroute(), where is under RTNL.

net->mpls.platform_label is only updated under RTNL.

Let's use rcu_dereference_rtnl() in mpls_route_input_rcu() to
silence the splat.

[0]:
WARNING: suspicious RCU usage
6.15.0-rc7-syzkaller-00082-g5cdb2c77c4c3 #0 Not tainted
 ----------------------------
net/mpls/af_mpls.c:84 suspicious rcu_dereference_check() usage!

other info that might help us debug this:

rcu_scheduler_active = 2, debug_locks = 1
1 lock held by syz.2.4451/17730:
 #0: ffffffff9012a3e8 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline]
 #0: ffffffff9012a3e8 (rtnl_mutex){+.+.}-{4:4}, at: rtnetlink_rcv_msg+0x371/0xe90 net/core/rtnetlink.c:6961

stack backtrace:
CPU: 1 UID: 0 PID: 17730 Comm: syz.2.4451 Not tainted 6.15.0-rc7-syzkaller-00082-g5cdb2c77c4c3 #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120
 lockdep_rcu_suspicious+0x166/0x260 kernel/locking/lockdep.c:6865
 mpls_route_input_rcu+0x1d4/0x200 net/mpls/af_mpls.c:84
 mpls_getroute+0x621/0x1ea0 net/mpls/af_mpls.c:2381
 rtnetlink_rcv_msg+0x3c9/0xe90 net/core/rtnetlink.c:6964
 netlink_rcv_skb+0x16d/0x440 net/netlink/af_netlink.c:2534
 netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]
 netlink_unicast+0x53a/0x7f0 net/netlink/af_netlink.c:1339
 netlink_sendmsg+0x8d1/0xdd0 net/netlink/af_netlink.c:1883
 sock_sendmsg_nosec net/socket.c:712 [inline]
 __sock_sendmsg net/socket.c:727 [inline]
 ____sys_sendmsg+0xa98/0xc70 net/socket.c:2566
 ___sys_sendmsg+0x134/0x1d0 net/socket.c:2620
 __sys_sendmmsg+0x200/0x420 net/socket.c:2709
 __do_sys_sendmmsg net/socket.c:2736 [inline]
 __se_sys_sendmmsg net/socket.c:2733 [inline]
 __x64_sys_sendmmsg+0x9c/0x100 net/socket.c:2733
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xcd/0x230 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f0a2818e969
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f0a28f52038 EFLAGS: 00000246 ORIG_RAX: 0000000000000133
RAX: ffffffffffffffda RBX: 00007f0a283b5fa0 RCX: 00007f0a2818e969
RDX: 0000000000000003 RSI: 0000200000000080 RDI: 0000000000000003
RBP: 00007f0a28210ab1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f0a283b5fa0 R15: 00007ffce5e9f268
 </TASK>

Fixes: 0189197f44 ("mpls: Basic routing support")
Reported-by: syzbot+8a583bdd1a5cc0b0e068@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/68507981.a70a0220.395abc.01ef.GAE@google.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250616201532.1036568-1-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:57 +01:00
..
6lowpan
9p 9p/xen: fix release of IRQ 2024-12-14 19:44:41 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: don't propagate flags on open 2025-05-02 07:39:11 +02:00
appletalk appletalk: Fix Use-After-Free in atalk_ioctl 2023-12-20 15:41:18 +01:00
atm atm: Revert atm_account_tx() if copy_from_iter_full() fails. 2025-06-27 11:02:56 +01:00
ax25
batman-adv batman-adv: Ignore own maximum aggregation size during RX 2025-04-10 14:29:38 +02:00
bluetooth Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION 2025-06-27 11:02:49 +01:00
bpf
bpfilter
bridge netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it 2025-06-27 11:02:46 +01:00
caif
can can: bcm: add missing rcu read protection for procfs content 2025-06-04 14:32:35 +02:00
ceph libceph: fix race between delayed_work() and ceph_monc_stop() 2024-07-18 11:40:55 +02:00
core sock: Correct error checking condition for (assign|release)_proto_idx() 2025-06-27 11:02:55 +01:00
dcb net: dcb: choose correct policy to parse DCB_ATTR_BCN 2023-08-11 11:53:57 +02:00
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa net: dsa: tag_sja1105: fix MAC DA patching from meta frames 2023-07-27 08:37:24 +02:00
ethernet ethernet: Add helper for assigning packet type when dest address does not match device address 2024-05-02 16:18:36 +02:00
hsr hsr: Handle failures in module init 2024-03-26 18:22:25 -04:00
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife net: sched: ife: fix potential use-after-free 2024-01-08 11:29:44 +01:00
ipv4 ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT 2025-06-27 11:02:54 +01:00
ipv6 netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy 2025-06-27 11:02:47 +01:00
iucv s390/iucv: fix receive buffer virtual vs physical address confusion 2024-09-04 13:14:57 +02:00
kcm kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
key net: af_key: fix sadb_x_filter validation 2023-08-30 16:27:16 +02:00
l2tp genetlink: hold RCU in genlmsg_mcast() 2024-11-08 16:20:50 +01:00
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 wifi: mac80211: do not offer a mesh path if forwarding is disabled 2025-06-27 11:02:55 +01:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). 2025-06-27 11:02:57 +01:00
ncsi net: ncsi: Fix GCPS 64-bit member variables 2025-06-27 11:02:46 +01:00
netfilter netfilter: nft_socket: fix sk refcount leaks 2025-06-27 11:02:44 +01:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink netlink: terminate outstanding dump on socket close 2024-12-14 19:44:18 +01:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: uart: Set tty->disc_data only in success path 2025-06-27 11:02:51 +01:00
nsh nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). 2024-05-17 11:43:49 +02:00
openvswitch openvswitch: Fix unsafe attribute parsing in output_userspace() 2025-06-04 14:32:29 +02:00
packet af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK 2025-01-09 13:23:35 +01:00
phonet phonet: fix rtm_phonet_notify() skb allocation 2024-05-17 11:43:54 +02:00
psample psample: Require 'CAP_NET_ADMIN' when joining "packets" group 2023-12-13 18:18:17 +01:00
qrtr net: qrtr: Update packets cloning when broadcasting 2024-11-08 16:20:33 +01:00
rds net:rds: Fix possible deadlock in rds_message_put 2024-09-04 13:15:03 +02:00
rfkill net: rfkill: gpio: Add check for clk_enable() 2024-12-14 19:44:27 +01:00
rose net: rose: lock the socket in rose_bind() 2025-03-13 12:43:06 +01:00
rxrpc rxrpc: Fix response to PING RESPONSE ACKs to a dead call 2024-02-23 08:25:07 +01:00
sched net_sched: tbf: fix a race in tbf_change() 2025-06-27 11:02:50 +01:00
sctp sctp: Do not wake readers in __sctp_write_space() 2025-06-27 11:02:54 +01:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser
sunrpc sunrpc: update nextcheck time when adding new cache entries 2025-06-27 11:02:53 +01:00
switchdev
tipc tipc: fix NULL pointer dereference in tipc_mon_reinit_self() 2025-05-02 07:39:25 +02:00
tls ktls, sockmap: Fix missing uncharge operation 2025-06-27 11:02:46 +01:00
unix af_unix: Remove put_pid()/put_cred() in copy_peercred(). 2024-09-12 11:03:52 +02:00
vmw_vsock vsock: avoid timeout during connect() if the socket is closing 2025-04-10 14:29:43 +02:00
wimax
wireless wifi: nl80211: reject cooked mode if it is set along with other flags 2025-03-13 12:43:28 +01:00
x25 net/x25: fix incorrect parameter validation in the x25_getsockopt() function 2024-03-26 18:22:18 -04:00
xdp xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING 2024-06-16 13:28:52 +02:00
xfrm xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c net: Save and restore msg_namelen in sock_sendmsg 2024-01-15 18:25:26 +01:00
sysctl_net.c