All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH net v5 0/2] amt: fix use-after-free of the skb head across pulls
@ 2026-07-11 15:19 Michael Bommarito
  2026-07-11 15:19 ` [PATCH net v5 1/2] amt: re-read skb header pointers after every pull Michael Bommarito
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Michael Bommarito @ 2026-07-11 15:19 UTC (permalink / raw)
  To: Taehee Yoo, Andrew Lunn, David S . Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni
  Cc: netdev, linux-kernel

Several AMT receive and transmit paths cache a pointer into the skb head
and then call a helper that can reallocate that head before the cached
pointer is used again, so the later access reads or writes freed memory.

Patch 1 walks every AMT path and, for each pointer used after a
reallocating call, either snapshots the value before the first pull or
re-derives the pointer after the last one.

Patch 2 is a smaller, separable hardening change: the three handlers
that rewrite the ethernet header do so in place without making the head
private, which corrupts a cloned skb (for example one held by a packet
tap).  It adds skb_cow_head() before the rewrite, split out so the
use-after-free fix is not held up by discussion of the clone case.

Both patches build cleanly (x86_64, CONFIG_AMT, W=1) and are
checkpatch --strict clean.

Changes since v4:
 - amt_update_handler(): also snapshot amtmu->nonce and
   amtmu->response_mac before iptunnel_pull_header(), which can
   reallocate the head for a GSO cloned skb; the tunnel-match loop read
   both fields through the stale amtmu.  This is the same class as the
   query handler's response_mac snapshot and was the one remaining site
   the v4 fix missed.
 - Remove the explanatory comments added in v4; the reason for each
   snapshot/re-derive is described in the commit message instead.
 - Order the local variable declarations longest-to-shortest in the
   handlers that gained locals (amt_membership_query_handler and
   amt_update_handler).

v4: https://lore.kernel.org/all/20260707193243.3448201-1-michael.bommarito@gmail.com/
v3: https://lore.kernel.org/all/20260626111917.802243-1-michael.bommarito@gmail.com/
v2: https://lore.kernel.org/all/20260617123443.3586930-1-michael.bommarito@gmail.com/

Michael Bommarito (2):
  amt: re-read skb header pointers after every pull
  amt: make the head writable before rewriting the L2 header

 drivers/net/amt.c | 87 ++++++++++++++++++++++++++++++++++++++++---------------
 1 file changed, 63 insertions(+), 24 deletions(-)


base-commit: 2c7c88a412aa6d09cd04b414211b4ef8553b5309
--
2.53.0

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-20 11:06 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-11 15:19 [PATCH net v5 0/2] amt: fix use-after-free of the skb head across pulls Michael Bommarito
2026-07-11 15:19 ` [PATCH net v5 1/2] amt: re-read skb header pointers after every pull Michael Bommarito
2026-07-11 15:19 ` [PATCH net v5 2/2] amt: make the head writable before rewriting the L2 header Michael Bommarito
2026-07-20 11:06 ` [PATCH net v5 0/2] amt: fix use-after-free of the skb head across pulls Simon Horman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.