From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.5 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_PASS, USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id A92C1C43381 for ; Tue, 12 Mar 2019 21:23:15 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 77AE3214AE for ; Tue, 12 Mar 2019 21:23:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1552425795; bh=t2j9r4o56VmkXPSlQht9Xa3cYc87rReWsO+k3yYN+LY=; h=Date:From:To:Cc:Subject:References:In-Reply-To:List-ID:From; b=vcyd1w2PlASqNUu7hYsP1nw2iIGre+IJ26PnPiM8AV7serxAp6AHnp5NhA2KTICdh HoLXMkEL81QlkD8U4MvPPbmpUug0nP2ryAcPzKzvmOBJwoE00osEWtQF9v98ZeARZm rMonRe30kEnEWUMtDzTquMUfRI9BperI3K/BRlcY= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726396AbfCLVXP (ORCPT ); Tue, 12 Mar 2019 17:23:15 -0400 Received: from mail.kernel.org ([198.145.29.99]:50610 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726378AbfCLVXP (ORCPT ); Tue, 12 Mar 2019 17:23:15 -0400 Received: from localhost (unknown [104.133.8.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 746482147C; Tue, 12 Mar 2019 21:23:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1552425793; bh=t2j9r4o56VmkXPSlQht9Xa3cYc87rReWsO+k3yYN+LY=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=BzHfCEN4wP3HsF0haSLYU7zQhtCt9mNK9bZqLWTTXcHyf4CHrNbAsG7iwf2D2LTNU leotpveIQ1AU0+LLPyiHdmcmZB1WlMzWqXqmhOfLl8533Vs+9EGY4rIwCndz23xbfO jO9AwylW/kHqnY80nGz5pUumwlCOBI7b1JR48Cn0= Date: Tue, 12 Mar 2019 14:23:12 -0700 From: Greg KH To: Zubin Mithra Cc: stable@vger.kernel.org, groeck@chromium.org, kadlec@blackhole.kfki.hu, sploving1@gmail.com, pablo@netfilter.org, fw@strlen.de, davem@davemloft.net Subject: Re: 644c7e48cb59 ("netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options") Message-ID: <20190312212312.GA12289@kroah.com> References: <20190312211049.GA108422@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20190312211049.GA108422@google.com> User-Agent: Mutt/1.11.3 (2019-02-01) Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org On Tue, Mar 12, 2019 at 02:10:50PM -0700, Zubin Mithra wrote: > Hello, > > Syzkaller has triggered a stack OOB read when fuzzing a 4.4 kernel with the following stacktrace. > Call Trace: > [] __dump_stack lib/dump_stack.c:15 [inline] > [] dump_stack+0xc1/0x124 lib/dump_stack.c:51 > [] print_address_description mm/kasan/report.c:192 [inline] > [] kasan_report_error mm/kasan/report.c:278 [inline] > [] kasan_report.part.2+0x44d/0x540 mm/kasan/report.c:303 > [] kasan_report mm/kasan/report.c:321 [inline] > [] __asan_report_load1_noabort+0x2e/0x30 mm/kasan/report.c:321 > [] tcp_options.isra.16+0x44b/0x490 net/netfilter/nf_conntrack_proto_tcp.c:413 > [] tcp_new+0x554/0x960 net/netfilter/nf_conntrack_proto_tcp.c:1138 > [] init_conntrack+0xed2/0x14d0 net/netfilter/nf_conntrack_core.c:951 > [] resolve_normal_ct net/netfilter/nf_conntrack_core.c:1049 [inline] > [] nf_conntrack_in+0xe40/0x13c0 net/netfilter/nf_conntrack_core.c:1138 > [] ipv4_conntrack_in+0x66/0x90 net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c:150 > [] nf_iterate+0x158/0x230 net/netfilter/core.c:276 > [] nf_hook_slow+0x1b5/0x320 net/netfilter/core.c:308 > [] nf_hook_thresh include/linux/netfilter.h:187 [inline] > [] NF_HOOK_THRESH include/linux/netfilter.h:224 [inline] > [] NF_HOOK include/linux/netfilter.h:249 [inline] > [] ip_rcv+0xe29/0x1380 net/ipv4/ip_input.c:455 > [] __netif_receive_skb_core+0xa6e/0x27c0 net/core/dev.c:4000 > [] __netif_receive_skb+0x60/0x1c0 net/core/dev.c:4035 > [] netif_receive_skb_internal+0xfe/0x380 net/core/dev.c:4063 > [] netif_receive_skb+0xa0/0x300 net/core/dev.c:4087 > [] tun_get_user+0xc93/0x2370 drivers/net/tun.c:1269 > [] tun_chr_write_iter+0xda/0x190 drivers/net/tun.c:1292 > [] new_sync_write fs/read_write.c:478 [inline] > [] __vfs_write+0x32e/0x440 fs/read_write.c:491 > [] vfs_write+0x16c/0x4a0 fs/read_write.c:538 > [] SYSC_write fs/read_write.c:585 [inline] > [] SyS_write+0xd9/0x1b0 fs/read_write.c:577 > [] entry_SYSCALL_64_fastpath+0x12/0x8d > > Could the following patch be applied v4.4.y? This patch is present in v4.9.y. > * 644c7e48cb59 ("netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options") > > > Tests run: > * Chrome OS tryjobs > * Syzkaller reproducer Now queued up, thanks. greg k-h