mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 09:20:13 -04:00
ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL
check when reading idev->cnf.rpl_seg_enabled.
When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears
dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev
check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with
dev->ip6_ptr already NULL.
Reproduced by flooding the receiving interface with ping6 traffic while
flapping its MTU between 1500 and 1200:
BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070
Read of size 4 at addr 00000000000006b4 by task ping6/394
CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)
Call Trace:
<IRQ>
kasan_report+0xc6/0x100
ipv6_rpl_srh_rcv+0xb3/0x1070
ip6_protocol_deliver_rcu+0x759/0x9a0
ip6_input_finish+0xa8/0x1b0
ip6_input+0xe1/0x490
ipv6_rcv+0x33d/0x460
__netif_receive_skb_one_core+0xd6/0x130
process_backlog+0x2cc/0xa00
__napi_poll.constprop.0+0x56/0x270
net_rx_action+0x327/0x730
handle_softirqs+0x11e/0x630
do_softirq+0xb3/0xf0
</IRQ>
Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from
ipv6_rthdr_rcv(), which already has an idev lookup.
Fix the NULL dereference on the RPL path by checking idev in
ipv6_rthdr_rcv(), before it calls either function. The callees take idev as
an argument and no longer call __in6_dev_get(), so the packet is now
dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.
Fixes: 8610c7c6e3 ("net: ipv6: add support for rpl sr exthdr")
Cc: stable@vger.kernel.org
Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Tested-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260817132644.2223-1-andrea.mayer@uniroma2.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
da4471557f
commit
f826df9533
@@ -368,23 +368,16 @@ static void seg6_update_csum(struct sk_buff *skb)
|
||||
(__be32 *)addr);
|
||||
}
|
||||
|
||||
static int ipv6_srh_rcv(struct sk_buff *skb)
|
||||
static int ipv6_srh_rcv(struct sk_buff *skb, struct inet6_dev *idev)
|
||||
{
|
||||
struct inet6_skb_parm *opt = IP6CB(skb);
|
||||
struct net *net = dev_net(skb->dev);
|
||||
struct ipv6_sr_hdr *hdr;
|
||||
struct inet6_dev *idev;
|
||||
struct in6_addr *addr;
|
||||
int accept_seg6;
|
||||
|
||||
hdr = (struct ipv6_sr_hdr *)skb_transport_header(skb);
|
||||
|
||||
idev = __in6_dev_get(skb->dev);
|
||||
if (!idev) {
|
||||
kfree_skb(skb);
|
||||
return -1;
|
||||
}
|
||||
|
||||
accept_seg6 = min(READ_ONCE(net->ipv6.devconf_all->seg6_enabled),
|
||||
READ_ONCE(idev->cnf.seg6_enabled));
|
||||
|
||||
@@ -485,12 +478,11 @@ static int ipv6_srh_rcv(struct sk_buff *skb)
|
||||
return -1;
|
||||
}
|
||||
|
||||
static int ipv6_rpl_srh_rcv(struct sk_buff *skb)
|
||||
static int ipv6_rpl_srh_rcv(struct sk_buff *skb, struct inet6_dev *idev)
|
||||
{
|
||||
struct ipv6_rpl_sr_hdr *hdr, *ohdr, *chdr;
|
||||
struct inet6_skb_parm *opt = IP6CB(skb);
|
||||
struct net *net = dev_net(skb->dev);
|
||||
struct inet6_dev *idev;
|
||||
struct ipv6hdr *oldhdr;
|
||||
unsigned int chdr_len;
|
||||
unsigned char *buf;
|
||||
@@ -499,8 +491,6 @@ static int ipv6_rpl_srh_rcv(struct sk_buff *skb)
|
||||
u64 n = 0;
|
||||
u32 r;
|
||||
|
||||
idev = __in6_dev_get(skb->dev);
|
||||
|
||||
accept_rpl_seg = min(READ_ONCE(net->ipv6.devconf_all->rpl_seg_enabled),
|
||||
READ_ONCE(idev->cnf.rpl_seg_enabled));
|
||||
if (!accept_rpl_seg) {
|
||||
@@ -689,10 +679,14 @@ static int ipv6_rthdr_rcv(struct sk_buff *skb)
|
||||
switch (hdr->type) {
|
||||
case IPV6_SRCRT_TYPE_4:
|
||||
/* segment routing */
|
||||
return ipv6_srh_rcv(skb);
|
||||
if (!idev)
|
||||
goto disabled;
|
||||
return ipv6_srh_rcv(skb, idev);
|
||||
case IPV6_SRCRT_TYPE_3:
|
||||
/* rpl segment routing */
|
||||
return ipv6_rpl_srh_rcv(skb);
|
||||
if (!idev)
|
||||
goto disabled;
|
||||
return ipv6_rpl_srh_rcv(skb, idev);
|
||||
default:
|
||||
break;
|
||||
}
|
||||
@@ -837,6 +831,10 @@ static int ipv6_rthdr_rcv(struct sk_buff *skb)
|
||||
icmpv6_param_prob(skb, ICMPV6_HDR_FIELD,
|
||||
(&hdr->type) - skb_network_header(skb));
|
||||
return -1;
|
||||
|
||||
disabled:
|
||||
kfree_skb_reason(skb, SKB_DROP_REASON_IPV6DISABLED);
|
||||
return -1;
|
||||
}
|
||||
|
||||
static const struct inet6_protocol rthdr_protocol = {
|
||||
|
||||
Reference in New Issue
Block a user