android_kernel_motorola_sm6375/include/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ricardo Cañuelo Navarro 5477622502 sctp: detect and prevent references to a freed transport in sendmsg
commit f1a69a940de58b16e8249dff26f74c8cc59b32be upstream.

sctp_sendmsg() re-uses associations and transports when possible by
doing a lookup based on the socket endpoint and the message destination
address, and then sctp_sendmsg_to_asoc() sets the selected transport in
all the message chunks to be sent.

There's a possible race condition if another thread triggers the removal
of that selected transport, for instance, by explicitly unbinding an
address with setsockopt(SCTP_SOCKOPT_BINDX_REM), after the chunks have
been set up and before the message is sent. This can happen if the send
buffer is full, during the period when the sender thread temporarily
releases the socket lock in sctp_wait_for_sndbuf().

This causes the access to the transport data in
sctp_outq_select_transport(), when the association outqueue is flushed,
to result in a use-after-free read.

This change avoids this scenario by having sctp_transport_free() signal
the freeing of the transport, tagging it as "dead". In order to do this,
the patch restores the "dead" bit in struct sctp_transport, which was
removed in
commit 47faa1e4c5 ("sctp: remove the dead field of sctp_transport").

Then, in the scenario where the sender thread has released the socket
lock in sctp_wait_for_sndbuf(), the bit is checked again after
re-acquiring the socket lock to detect the deletion. This is done while
holding a reference to the transport to prevent it from being freed in
the process.

If the transport was deleted while the socket lock was relinquished,
sctp_sendmsg_to_asoc() will return -EAGAIN to let userspace retry the
send.

The bug was found by a private syzbot instance (see the error report [1]
and the C reproducer that triggers it [2]).

Link: https://people.igalia.com/rcn/kernel_logs/20250402__KASAN_slab-use-after-free_Read_in_sctp_outq_select_transport.txt [1]
Link: https://people.igalia.com/rcn/kernel_logs/20250402__KASAN_slab-use-after-free_Read_in_sctp_outq_select_transport__repro.c [2]
Cc: stable@vger.kernel.org
Fixes: df132eff46 ("sctp: clear the transport of some out_chunk_list chunks in sctp_assoc_rm_peer")
Suggested-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: Ricardo Cañuelo Navarro <rcn@igalia.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20250404-kasan_slab-use-after-free_read_in_sctp_outq_select_transport__20250404-v1-1-5ce4a0b78ef2@igalia.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-05-02 07:39:16 +02:00
..
9p
bluetooth Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ 2024-07-05 09:08:17 +02:00
caif
iucv
netfilter netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext 2025-01-09 13:23:35 +01:00
netns ipv6: make ip6_rt_gc_expire an atomic_t 2024-01-15 18:25:29 +01:00
nfc nfc: constify several pointers to u8, char and sk_buff 2023-07-27 08:37:07 +02:00
phonet
sctp sctp: detect and prevent references to a freed transport in sendmsg 2025-05-02 07:39:16 +02:00
tc_act net/sched: act_pedit: really ensure the skb is writable 2022-05-18 09:47:25 +02:00
6lowpan.h
act_api.h
addrconf.h ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr 2024-05-02 16:18:28 +02:00
af_ieee802154.h
af_rxrpc.h
af_unix.h af_unix: Suppress false-positive lockdep splat for spin_lock() in __unix_gc(). 2024-05-02 16:18:35 +02:00
af_vsock.h
ah.h
arp.h
atmclip.h
ax25.h ax25: fix reference count leaks of ax25_dev 2022-04-20 09:19:39 +02:00
ax88796.h
bond_3ad.h
bond_alb.h bonding (gcc13): synchronize bond_{a,t}lb_xmit() types 2023-06-14 10:59:58 +02:00
bond_options.h
bonding.h bonding: fix macvlan over alb bond support 2023-08-30 16:27:24 +02:00
bpf_sk_storage.h
busy_poll.h net: busy-poll: use ktime_get_ns() instead of local_clock() 2024-09-04 13:15:03 +02:00
calipso.h
cfg80211-wext.h
cfg80211.h wifi: cfg80211: fix sband iftype data lookup for AP_VLAN 2023-08-16 18:19:24 +02:00
cfg802154.h
checksum.h
cipso_ipv4.h
cls_cgroup.h
codel.h
codel_impl.h
codel_qdisc.h
compat.h
datalink.h
dcbevent.h
dcbnl.h
devlink.h
drop_monitor.h
dsa.h
dsfield.h
dst.h net: Remove unused inline function dst_hold_and_use() 2023-06-21 15:44:12 +02:00
dst_cache.h
dst_metadata.h
dst_ops.h net: fix __dst_negative_advice() race 2024-06-16 13:28:52 +02:00
erspan.h erspan: Add type I version 0 support. 2024-04-13 12:51:36 +02:00
esp.h esp: limit skb_page_frag_refill use to a single page 2022-07-12 16:30:45 +02:00
ethoc.h
failover.h
fib_notifier.h
fib_rules.h
firewire.h
flow.h inet: shrink struct flowi_common 2023-11-20 10:30:15 +01:00
flow_dissector.h net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
flow_offload.h net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
fou.h
fq.h
fq_impl.h
garp.h
gen_stats.h
genetlink.h genetlink: hold RCU in genlmsg_mcast() 2024-11-08 16:20:50 +01:00
geneve.h
gre.h
gro_cells.h
gtp.h
gue.h
hwbm.h
icmp.h
ieee80211_radiotap.h
ieee802154_netdev.h net: ieee802154: return -EINVAL for unknown addr type 2022-10-26 13:22:59 +02:00
if_inet6.h net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX 2023-12-20 15:41:13 +01:00
ife.h
ila.h
inet6_connection_sock.h
inet6_hashtables.h
inet_common.h
inet_connection_sock.h tcp/dccp: allow a connection when sk_max_ack_backlog is zero 2025-02-01 18:18:45 +01:00
inet_ecn.h
inet_frag.h
inet_hashtables.h secure_seq: use the 64 bits of the siphash for port offset calculation 2022-06-06 08:33:49 +02:00
inet_sock.h tcp/dccp: Fix a data-race around sysctl_tcp_fwmark_accept. 2022-07-29 17:14:11 +02:00
inet_timewait_sock.h
inetpeer.h
ip.h ipv{4,6}/raw: fix output xfrm lookup wrt protocol 2023-06-05 08:17:33 +02:00
ip6_checksum.h
ip6_fib.h
ip6_route.h
ip6_tunnel.h ip_gre, ip6_gre: Fix race condition on o_seqno in collect_md mode 2023-05-30 12:44:05 +01:00
ip_fib.h
ip_tunnels.h geneve: fix header validation in geneve[6]_xmit_skb 2024-05-02 16:18:28 +02:00
ip_vs.h
ipcomp.h
ipconfig.h
ipv6.h tcp: Reduce chance of collisions in inet6_hashfn(). 2023-08-11 11:53:47 +02:00
ipv6_frag.h
ipv6_stubs.h
ipx.h
iw_handler.h
kcm.h kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
l3mdev.h vrf: use RCU protection in l3mdev_l3_out() 2025-03-13 12:43:12 +01:00
lag.h
lapb.h net: lapb: increase LAPB_HEADER_LEN 2024-12-19 18:05:03 +01:00
lib80211.h
llc.h
llc_c_ac.h
llc_c_ev.h
llc_c_st.h
llc_conn.h
llc_if.h
llc_pdu.h llc: Drop support for ETH_P_TR_802_2. 2024-02-23 08:24:50 +01:00
llc_s_ac.h
llc_s_ev.h
llc_s_st.h
llc_sap.h
lwtunnel.h lwt: Check LWTUNNEL_XMIT_CONTINUE strictly 2023-09-23 10:59:42 +02:00
mac80211.h mac80211: Add support to trigger sta disconnect on hardware restart 2024-11-08 16:20:52 +01:00
mac802154.h
mip6.h
mld.h
mpls.h
mpls_iptunnel.h
mrp.h mrp: introduce active flags to prevent UAF when applicant uninit 2023-01-18 11:41:37 +01:00
ncsi.h
ndisc.h
neighbour.h neighbour: delete neigh_lookup_nodev as not used 2023-06-21 15:44:12 +02:00
net_failover.h
net_namespace.h net: add dev_net_rcu() helper 2025-03-13 12:43:17 +01:00
net_ratelimit.h
netevent.h
netlabel.h
netlink.h
netprio_cgroup.h
netrom.h
nexthop.h
nl802154.h
nsh.h
p8022.h
page_pool.h
ping.h
pkt_cls.h
pkt_sched.h net/sched: make psched_mtu() RTNL-less safe 2023-07-27 08:37:33 +02:00
pptp.h
protocol.h tcp/udp: Make early_demux back namespacified. 2022-11-10 17:57:55 +01:00
psample.h
psnap.h
raw.h raw: Fix a data-race around sysctl_raw_l3mdev_accept. 2022-07-21 20:59:22 +02:00
rawv6.h
red.h
regulatory.h
request_sock.h
rose.h
route.h
rsi_91x.h
rtnetlink.h net: validate veth and vxcan peer ifindexes 2023-08-30 16:27:24 +02:00
rtnh.h
sch_generic.h net/sched: accept TCA_STAB only for root qdisc 2024-11-08 16:20:45 +01:00
scm.h scm: fix MSG_CTRUNC setting condition for SO_PASSSEC 2023-05-17 11:35:41 +02:00
secure_seq.h secure_seq: use the 64 bits of the siphash for port offset calculation 2022-06-06 08:33:49 +02:00
seg6.h
seg6_hmac.h
seg6_local.h
slhc_vj.h
smc.h
snmp.h
sock.h net: Fix an unsafe loop on the list 2024-11-08 16:20:47 +01:00
sock_reuseport.h
Space.h
stp.h
strparser.h
switchdev.h
tcp.h tcp: check skb is non-NULL in tcp_rto_delta_us() 2024-11-08 16:20:33 +01:00
tcp_states.h
timewait_sock.h
tipc.h
tls.h
transp_v6.h
tso.h
tun_proto.h
udp.h tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct(). 2023-04-26 11:24:05 +02:00
udp_tunnel.h
udplite.h tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct(). 2023-04-26 11:24:05 +02:00
vsock_addr.h
vxlan.h vxlan: calculate correct header length for GPE 2023-08-11 11:53:47 +02:00
wext.h
wimax.h
x25.h
x25device.h
xdp.h
xdp_priv.h
xdp_sock.h
xfrm.h xfrm: Preserve vlan tags for transport mode software GRO 2024-05-17 11:43:53 +02:00