Kuniyuki Iwashima
2919297b18
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
[ Upstream commit 6dbb0d97c5096072c78a6abffe393584e57ae945 ]
As syzbot reported [0], mpls_route_input_rcu() can be called
from mpls_getroute(), where is under RTNL.
net->mpls.platform_label is only updated under RTNL.
Let's use rcu_dereference_rtnl() in mpls_route_input_rcu() to
silence the splat.
[0]:
WARNING: suspicious RCU usage
6.15.0-rc7-syzkaller-00082-g5cdb2c77c4c3 #0 Not tainted
----------------------------
net/mpls/af_mpls.c:84 suspicious rcu_dereference_check() usage!
other info that might help us debug this:
rcu_scheduler_active = 2, debug_locks = 1
1 lock held by syz.2.4451/17730:
#0: ffffffff9012a3e8 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline]
#0: ffffffff9012a3e8 (rtnl_mutex){+.+.}-{4:4}, at: rtnetlink_rcv_msg+0x371/0xe90 net/core/rtnetlink.c:6961
stack backtrace:
CPU: 1 UID: 0 PID: 17730 Comm: syz.2.4451 Not tainted 6.15.0-rc7-syzkaller-00082-g5cdb2c77c4c3 #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120
lockdep_rcu_suspicious+0x166/0x260 kernel/locking/lockdep.c:6865
mpls_route_input_rcu+0x1d4/0x200 net/mpls/af_mpls.c:84
mpls_getroute+0x621/0x1ea0 net/mpls/af_mpls.c:2381
rtnetlink_rcv_msg+0x3c9/0xe90 net/core/rtnetlink.c:6964
netlink_rcv_skb+0x16d/0x440 net/netlink/af_netlink.c:2534
netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]
netlink_unicast+0x53a/0x7f0 net/netlink/af_netlink.c:1339
netlink_sendmsg+0x8d1/0xdd0 net/netlink/af_netlink.c:1883
sock_sendmsg_nosec net/socket.c:712 [inline]
__sock_sendmsg net/socket.c:727 [inline]
____sys_sendmsg+0xa98/0xc70 net/socket.c:2566
___sys_sendmsg+0x134/0x1d0 net/socket.c:2620
__sys_sendmmsg+0x200/0x420 net/socket.c:2709
__do_sys_sendmmsg net/socket.c:2736 [inline]
__se_sys_sendmmsg net/socket.c:2733 [inline]
__x64_sys_sendmmsg+0x9c/0x100 net/socket.c:2733
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x230 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f0a2818e969
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f0a28f52038 EFLAGS: 00000246 ORIG_RAX: 0000000000000133
RAX: ffffffffffffffda RBX: 00007f0a283b5fa0 RCX: 00007f0a2818e969
RDX: 0000000000000003 RSI: 0000200000000080 RDI: 0000000000000003
RBP: 00007f0a28210ab1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f0a283b5fa0 R15: 00007ffce5e9f268
</TASK>
Fixes: 0189197f44 ("mpls: Basic routing support")
Reported-by: syzbot+8a583bdd1a5cc0b0e068@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/68507981.a70a0220.395abc.01ef.GAE@google.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250616201532.1036568-1-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2025-06-27 11:02:57 +01:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p/xen: fix release of IRQ
|
2024-12-14 19:44:41 +01:00 |
|
802
|
net: 802: LLC+SNAP OID:PID lookup on start of skb data
|
2025-02-01 18:18:45 +01:00 |
|
8021q
|
net: vlan: don't propagate flags on open
|
2025-05-02 07:39:11 +02:00 |
|
appletalk
|
appletalk: Fix Use-After-Free in atalk_ioctl
|
2023-12-20 15:41:18 +01:00 |
|
atm
|
atm: Revert atm_account_tx() if copy_from_iter_full() fails.
|
2025-06-27 11:02:56 +01:00 |
|
ax25
|
|
|
|
batman-adv
|
batman-adv: Ignore own maximum aggregation size during RX
|
2025-04-10 14:29:38 +02:00 |
|
bluetooth
|
Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
|
2025-06-27 11:02:49 +01:00 |
|
bpf
|
|
|
|
bpfilter
|
|
|
|
bridge
|
netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
|
2025-06-27 11:02:46 +01:00 |
|
caif
|
|
|
|
can
|
can: bcm: add missing rcu read protection for procfs content
|
2025-06-04 14:32:35 +02:00 |
|
ceph
|
libceph: fix race between delayed_work() and ceph_monc_stop()
|
2024-07-18 11:40:55 +02:00 |
|
core
|
sock: Correct error checking condition for (assign|release)_proto_idx()
|
2025-06-27 11:02:55 +01:00 |
|
dcb
|
net: dcb: choose correct policy to parse DCB_ATTR_BCN
|
2023-08-11 11:53:57 +02:00 |
|
dccp
|
net: fix data-races around sk->sk_forward_alloc
|
2025-02-01 18:18:52 +01:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: tag_sja1105: fix MAC DA patching from meta frames
|
2023-07-27 08:37:24 +02:00 |
|
ethernet
|
ethernet: Add helper for assigning packet type when dest address does not match device address
|
2024-05-02 16:18:36 +02:00 |
|
hsr
|
hsr: Handle failures in module init
|
2024-03-26 18:22:25 -04:00 |
|
ieee802154
|
net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
|
2024-12-14 19:44:51 +01:00 |
|
ife
|
net: sched: ife: fix potential use-after-free
|
2024-01-08 11:29:44 +01:00 |
|
ipv4
|
ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
|
2025-06-27 11:02:54 +01:00 |
|
ipv6
|
netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
|
2025-06-27 11:02:47 +01:00 |
|
iucv
|
s390/iucv: fix receive buffer virtual vs physical address confusion
|
2024-09-04 13:14:57 +02:00 |
|
kcm
|
kcm: Serialise kcm_sendmsg() for the same socket.
|
2024-09-04 13:14:59 +02:00 |
|
key
|
net: af_key: fix sadb_x_filter validation
|
2023-08-30 16:27:16 +02:00 |
|
l2tp
|
genetlink: hold RCU in genlmsg_mcast()
|
2024-11-08 16:20:50 +01:00 |
|
l3mdev
|
|
|
|
lapb
|
|
|
|
llc
|
llc: fix data loss when reading from a socket in llc_ui_recvmsg()
|
2025-06-04 14:32:35 +02:00 |
|
mac80211
|
wifi: mac80211: do not offer a mesh path if forwarding is disabled
|
2025-06-27 11:02:55 +01:00 |
|
mac802154
|
mac802154: check local interfaces before deleting sdata list
|
2025-02-01 18:18:50 +01:00 |
|
mpls
|
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
|
2025-06-27 11:02:57 +01:00 |
|
ncsi
|
net: ncsi: Fix GCPS 64-bit member variables
|
2025-06-27 11:02:46 +01:00 |
|
netfilter
|
netfilter: nft_socket: fix sk refcount leaks
|
2025-06-27 11:02:44 +01:00 |
|
netlabel
|
calipso: unlock rcu before returning -EAFNOSUPPORT
|
2025-06-27 11:02:50 +01:00 |
|
netlink
|
netlink: terminate outstanding dump on socket close
|
2024-12-14 19:44:18 +01:00 |
|
netrom
|
netrom: check buffer length before accessing it
|
2025-01-09 13:23:35 +01:00 |
|
nfc
|
NFC: nci: uart: Set tty->disc_data only in success path
|
2025-06-27 11:02:51 +01:00 |
|
nsh
|
nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
|
2024-05-17 11:43:49 +02:00 |
|
openvswitch
|
openvswitch: Fix unsafe attribute parsing in output_userspace()
|
2025-06-04 14:32:29 +02:00 |
|
packet
|
af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
|
2025-01-09 13:23:35 +01:00 |
|
phonet
|
phonet: fix rtm_phonet_notify() skb allocation
|
2024-05-17 11:43:54 +02:00 |
|
psample
|
psample: Require 'CAP_NET_ADMIN' when joining "packets" group
|
2023-12-13 18:18:17 +01:00 |
|
qrtr
|
net: qrtr: Update packets cloning when broadcasting
|
2024-11-08 16:20:33 +01:00 |
|
rds
|
net:rds: Fix possible deadlock in rds_message_put
|
2024-09-04 13:15:03 +02:00 |
|
rfkill
|
net: rfkill: gpio: Add check for clk_enable()
|
2024-12-14 19:44:27 +01:00 |
|
rose
|
net: rose: lock the socket in rose_bind()
|
2025-03-13 12:43:06 +01:00 |
|
rxrpc
|
rxrpc: Fix response to PING RESPONSE ACKs to a dead call
|
2024-02-23 08:25:07 +01:00 |
|
sched
|
net_sched: tbf: fix a race in tbf_change()
|
2025-06-27 11:02:50 +01:00 |
|
sctp
|
sctp: Do not wake readers in __sctp_write_space()
|
2025-06-27 11:02:54 +01:00 |
|
smc
|
net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
|
2025-01-09 13:23:27 +01:00 |
|
strparser
|
|
|
|
sunrpc
|
sunrpc: update nextcheck time when adding new cache entries
|
2025-06-27 11:02:53 +01:00 |
|
switchdev
|
|
|
|
tipc
|
tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
|
2025-05-02 07:39:25 +02:00 |
|
tls
|
ktls, sockmap: Fix missing uncharge operation
|
2025-06-27 11:02:46 +01:00 |
|
unix
|
af_unix: Remove put_pid()/put_cred() in copy_peercred().
|
2024-09-12 11:03:52 +02:00 |
|
vmw_vsock
|
vsock: avoid timeout during connect() if the socket is closing
|
2025-04-10 14:29:43 +02:00 |
|
wimax
|
|
|
|
wireless
|
wifi: nl80211: reject cooked mode if it is set along with other flags
|
2025-03-13 12:43:28 +01:00 |
|
x25
|
net/x25: fix incorrect parameter validation in the x25_getsockopt() function
|
2024-03-26 18:22:18 -04:00 |
|
xdp
|
xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
|
2024-06-16 13:28:52 +02:00 |
|
xfrm
|
xfrm: Sanitize marks before insert
|
2025-06-04 14:32:35 +02:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
net: Save and restore msg_namelen in sock_sendmsg
|
2024-01-15 18:25:26 +01:00 |
|
sysctl_net.c
|
|
|