android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Subash Abhinov Kasiviswanathan de256ffb4a netfilter: x_tables: Switch synchronization to RCU
When running concurrent iptables rules replacement with data, the per CPU
sequence count is checked after the assignment of the new information.
The sequence count is used to synchronize with the packet path without the
use of any explicit locking. If there are any packets in the packet path
using the table information, the sequence count is incremented to an odd
value and is incremented to an even after the packet process completion.

The new table value assignment is followed by a write memory barrier so
every CPU should see the latest value. If the packet path has started with
the old table information, the sequence counter will be odd and the
iptables replacement will wait till the sequence count is even prior to
freeing the old table info.

However, this assumes that the new table information assignment and the
memory barrier is actually executed prior to the counter check in the
replacement thread. If CPU decides to execute the assignment later as there
is no user of the table information prior to the sequence check, the packet
path in another CPU may use the old table information. The replacement
thread would then free the table information under it leading to a use
after free in the packet processing context-

Unable to handle kernel NULL pointer dereference at virtual
address 000000000000008e
pc : ip6t_do_table+0x5d0/0x89c
lr : ip6t_do_table+0x5b8/0x89c
ip6t_do_table+0x5d0/0x89c
ip6table_filter_hook+0x24/0x30
nf_hook_slow+0x84/0x120
ip6_input+0x74/0xe0
ip6_rcv_finish+0x7c/0x128
ipv6_rcv+0xac/0xe4
__netif_receive_skb+0x84/0x17c
process_backlog+0x15c/0x1b8
napi_poll+0x88/0x284
net_rx_action+0xbc/0x23c
__do_softirq+0x20c/0x48c

This could be fixed by forcing instruction order after the new table
information assignment or by switching to RCU for the synchronization.

Change-Id: I41ffb931b711cd2de9896d9ca7f13dda79e6709f
Signed-off-by: Subash Abhinov Kasiviswanathan <subashab@codeaurora.org>
2020-12-09 10:18:47 -08:00
..
6lowpan
9p net/9p: validate fds in p9_fd_open 2020-08-11 15:33:36 +02:00
802
8021q
appletalk appletalk: Fix atalk_proc_init() return path 2020-08-11 15:33:40 +02:00
atm
ax25 AX.25: Prevent integer overflows in connect and sendmsg 2020-07-31 18:39:31 +02:00
batman-adv batman-adv: Revert "disable ethtool link speed detection when auto negotiation off" 2020-06-22 09:30:56 +02:00
bluetooth Bluetooth: add a mutex lock to avoid UAF in do_enale_set 2020-08-19 08:15:59 +02:00
bpf
bpfilter
bridge bridge: Add bridge API to access the bridge slave port 2020-11-10 19:36:12 -08:00
caif ANDROID: GKI: Fix up "do not export symbol_get/put()" commit 2020-08-01 14:28:51 +02:00
can can: j1939: add rxtimer for multipacket broadcast session 2020-08-26 10:41:02 +02:00
ceph libceph: don't omit recovery_deletes in target_copy() 2020-07-22 09:33:17 +02:00
core Merge "Merge android11-5.4.61+ (3720133) into msm-5.4" 2020-12-01 02:17:29 -08:00
dcb
dccp dccp: Fix possible memleak in dccp_init and dccp_fini 2020-06-17 16:40:32 +02:00
decnet
dns_resolver KEYS: Don't write out to userspace while holding key semaphore 2020-04-23 10:36:45 +02:00
dsa net: dsa: declare lockless TX feature for slave ports 2020-06-03 08:21:38 +02:00
embms_kernel net/embms-kernel : EMBMS Tunneling Module 2020-10-16 18:23:27 +05:30
ethernet
hsr
ieee802154
ife
ipv4 netfilter: x_tables: Switch synchronization to RCU 2020-12-09 10:18:47 -08:00
ipv6 netfilter: x_tables: Switch synchronization to RCU 2020-12-09 10:18:47 -08:00
iucv
kcm
key xfrm: policy: match with both mark and mask on user interfaces 2020-08-05 09:59:44 +02:00
l2tp l2tp: remove skb_dst_set() from l2tp_xmit_skb() 2020-07-22 09:32:47 +02:00
l3mdev
lapb
llc llc: make sure applications use ARPHRD_ETHER 2020-07-22 09:32:47 +02:00
mac80211 UPSTREAM: mac80211: fix warning in 6 GHz IE addition in mesh mode 2020-11-14 16:29:38 +01:00
mac802154
mpls
ncsi
netfilter netfilter: x_tables: Switch synchronization to RCU 2020-12-09 10:18:47 -08:00
netlabel netlabel: cope with NULL catmap 2020-05-20 08:20:08 +02:00
netlink Revert "Revert "genetlink: remove genl_bind"" 2020-08-13 15:45:33 +02:00
netrom net: netrom: Fix potential nr_neigh refcnt leak in nr_add_node 2020-04-29 16:33:08 +02:00
neuron net: neuron: channel: Check buffer boundaries 2020-11-12 15:09:46 -08:00
nfc net/nfc/rawsock.c: add CAP_NET_RAW check. 2020-08-19 08:16:22 +02:00
nsh
openvswitch openvswitch: Prevent kernel-infoleak in ovs_ct_put_key() 2020-08-11 15:33:41 +02:00
packet af_packet: TPACKET_V3: fix fill status rwlock imbalance 2020-08-19 08:16:22 +02:00
phonet
psample
qrtr net: qrtr: Make wakeup timeout configurable 2020-11-05 13:45:07 -08:00
rds rds: Prevent kernel-infoleak in rds_notify_queue_get() 2020-08-05 09:59:44 +02:00
rfkill
rose
rxrpc rxrpc: Fix race between recvmsg and sendmsg on immediate call failure 2020-08-11 15:33:40 +02:00
sched sched: consistently handle layer3 header accesses in the presence of VLANs 2020-07-22 09:32:48 +02:00
sctp This is the 5.4.55 stable release 2020-08-01 11:46:55 +02:00
smc
strparser
sunrpc svcrdma: Fix another Receive buffer leak 2020-08-26 10:40:55 +02:00
switchdev
tipc tipc: block BH before using dst_cache 2020-06-03 08:21:03 +02:00
tls net/tls: Fix kmap usage 2020-08-19 08:16:23 +02:00
unix
vmw_vsock vsock/virtio: annotate 'the_virtio_vsock' RCU pointer 2020-07-29 10:18:31 +02:00
wimax
wireless Merge "cfg80211: export regulatory_hint_user() API" 2020-12-02 03:04:39 -08:00
x25 net/x25: Fix null-ptr-deref in x25_disconnect 2020-08-05 09:59:44 +02:00
xdp xdp: Fix xsk_generic_xmit errno 2020-06-24 17:50:44 +02:00
xfrm ANDROID: Temporarily disable XFRM_USER_COMPAT filtering 2020-11-05 21:08:28 +00:00
compat.c Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4" 2020-08-23 13:12:51 +02:00
Kconfig net: Kconfig changes to enable sfe feature 2020-11-19 21:43:13 -08:00
Makefile
socket.c This is the 5.4.59 stable release 2020-08-19 08:40:57 +02:00
sysctl_net.c