android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Pedro Tammela e5bee633cc net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
commit ac9fe7dd8e730a103ae4481147395cc73492d786 upstream.

Savino says:
    "We are writing to report that this recent patch
    (141d34391abbb315d68556b7c67ad97885407547) [1]
    can be bypassed, and a UAF can still occur when HFSC is utilized with
    NETEM.

    The patch only checks the cl->cl_nactive field to determine whether
    it is the first insertion or not [2], but this field is only
    incremented by init_vf [3].

    By using HFSC_RSC (which uses init_ed) [4], it is possible to bypass the
    check and insert the class twice in the eltree.
    Under normal conditions, this would lead to an infinite loop in
    hfsc_dequeue for the reasons we already explained in this report [5].

    However, if TBF is added as root qdisc and it is configured with a
    very low rate,
    it can be utilized to prevent packets from being dequeued.
    This behavior can be exploited to perform subsequent insertions in the
    HFSC eltree and cause a UAF."

To fix both the UAF and the infinite loop, with netem as an hfsc child,
check explicitly in hfsc_enqueue whether the class is already in the eltree
whenever the HFSC_RSC flag is set.

[1] https://web.git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=141d34391abbb315d68556b7c67ad97885407547
[2] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L1572
[3] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L677
[4] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L1574
[5] https://lore.kernel.org/netdev/8DuRWwfqjoRDLDmBMlIfbrsZg9Gx50DHJc1ilxsEBNe2D6NMoigR_eIRIG0LOjMc3r10nUUZtArXx4oZBIdUfZQrwjcQhdinnMis_0G7VEk=@willsroot.io/T/#u

Fixes: 37d9cf1a3c ("sched: Fix detection of empty queues in child qdiscs")
Reported-by: Savino Dicanosa <savy@syst3mfailure.io>
Reported-by: William Liu <will@willsroot.io>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Link: https://patch.msgid.link/20250522181448.1439717-2-pctammela@mojatatu.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-04 14:32:36 +02:00
..
6lowpan
9p 9p/xen: fix release of IRQ 2024-12-14 19:44:41 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: don't propagate flags on open 2025-05-02 07:39:11 +02:00
appletalk
atm atm: Fix NULL pointer dereference 2025-04-10 14:29:38 +02:00
ax25
batman-adv batman-adv: Ignore own maximum aggregation size during RX 2025-04-10 14:29:38 +02:00
bluetooth Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for invalid address 2025-05-02 07:39:19 +02:00
bpf
bpfilter
bridge bridge: netfilter: Fix forwarding of fragmented packets 2025-06-04 14:32:35 +02:00
caif
can can: bcm: add missing rcu read protection for procfs content 2025-06-04 14:32:35 +02:00
ceph libceph: fix race between delayed_work() and ceph_monc_stop() 2024-07-18 11:40:55 +02:00
core net: pktgen: fix access outside of user given buffer in pktgen_thread_write() 2025-06-04 14:32:33 +02:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa
ethernet
hsr
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife
ipv4 ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure(). 2025-06-04 14:32:34 +02:00
ipv6 ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure(). 2025-06-04 14:32:34 +02:00
iucv s390/iucv: fix receive buffer virtual vs physical address confusion 2024-09-04 13:14:57 +02:00
kcm kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
key
l2tp genetlink: hold RCU in genlmsg_mcast() 2024-11-08 16:20:50 +01:00
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 Revert "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()" 2025-05-02 07:39:19 +02:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls
ncsi net/ncsi: wait for the last response to Deselect Package before configuring channel 2025-03-13 12:43:11 +01:00
netfilter netfilter: nf_tables: do not defer rule destruction via call_rcu 2025-06-04 14:32:36 +02:00
netlabel
netlink netlink: terminate outstanding dump on socket close 2024-12-14 19:44:18 +01:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: Add bounds checking in nci_hci_create_pipe() 2025-03-13 12:43:11 +01:00
nsh
openvswitch openvswitch: Fix unsafe attribute parsing in output_userspace() 2025-06-04 14:32:29 +02:00
packet af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK 2025-01-09 13:23:35 +01:00
phonet
psample
qrtr net: qrtr: Update packets cloning when broadcasting 2024-11-08 16:20:33 +01:00
rds net:rds: Fix possible deadlock in rds_message_put 2024-09-04 13:15:03 +02:00
rfkill net: rfkill: gpio: Add check for clk_enable() 2024-12-14 19:44:27 +01:00
rose net: rose: lock the socket in rose_bind() 2025-03-13 12:43:06 +01:00
rxrpc
sched net_sched: hfsc: Address reentrant enqueue adding class to eltree twice 2025-06-04 14:32:36 +02:00
sctp sctp: detect and prevent references to a freed transport in sendmsg 2025-05-02 07:39:16 +02:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser
sunrpc SUNRPC: rpc_clnt_set_transport() must not change the autobind setting 2025-06-04 14:32:30 +02:00
switchdev
tipc tipc: fix NULL pointer dereference in tipc_mon_reinit_self() 2025-05-02 07:39:25 +02:00
tls tls: Fix tls_sw_sendmsg error handling 2025-02-01 18:18:45 +01:00
unix af_unix: Remove put_pid()/put_cred() in copy_peercred(). 2024-09-12 11:03:52 +02:00
vmw_vsock vsock: avoid timeout during connect() if the socket is closing 2025-04-10 14:29:43 +02:00
wimax
wireless wifi: nl80211: reject cooked mode if it is set along with other flags 2025-03-13 12:43:28 +01:00
x25
xdp
xfrm xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c