From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f178.google.com (mail-qt1-f178.google.com [209.85.160.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E831C3A1B5 for ; Fri, 31 Jul 2026 14:07:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785506823; cv=none; b=l0LzKNxL2VlkGrNjHPEDpgpVWbTbBGNHj8fWVI8eZN0Fg/vwEKh366tnc7WTe43wNwwlg13HXomgsNQgp2S8kgWCU7//izVrNida2Wb8hrserCFwK+peE+9jkiPSECiycGy4un6iNDSgBWZBMDj/fsJyjKFyNicX02braH2cc5k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785506823; c=relaxed/simple; bh=yIeApXitfnS8CcqsGXBvonkx8fP0b42QxgWsMsjIYqs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=QnCjtJmpYyQyiFnn+nzUYbl30xTDyLM3SuSQNEoBAA8ivM7ISxSpbPlM3oue4xl3b7q9ZAw2MIGus5e8xG3s+GfRyd8lGMTvG8mb/3JsyBvr4/cDfaqHB37JIeauCSv6Q65EE0L9spn0DDLTzWHoPiKvDsAFaJTNhaubZ/a3HS4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=RfymgeYS; arc=none smtp.client-ip=209.85.160.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="RfymgeYS" Received: by mail-qt1-f178.google.com with SMTP id d75a77b69052e-51c2cce930cso8620051cf.0 for ; Fri, 31 Jul 2026 07:07:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785506821; x=1786111621; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=skmn0gc4hRDxdVRgF7HwpzhsoE62D6T+gwWSKWR4PIs=; b=RfymgeYSCG6IEPWe9FpT6m56O7onUyqrvak7jnPgonNjpMByxEK62NnjRj9VuaNn59 NsoT0EwXPXd+IX1AhKBNpkIi6ssuFArmlrtyVG0ePNBHUjwgqG7u0/fwhvDsQLENZMs+ 9WvFnFNFx8AHWUM2y3LEvJrr8LVUE9uYwGScsxlG/EIiE74wiPCcMPFxZujEYqIVyqpO UoRVXU23yv7xUfXc6iJYsgmep4314VFcxyb3p/kRoJmn1C0YUiitG3n6d/KiDKYVqL8/ kqP7caVqIyE7HMG+mdF2twudP2ieLOdH48CTz/MmWYFiQe7ufplsOzmhfPUFtzjupSVz lqEg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785506821; x=1786111621; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=skmn0gc4hRDxdVRgF7HwpzhsoE62D6T+gwWSKWR4PIs=; b=b0aOv87epFR9xc4QHpNRC1S4YiJzo+ss1drEdOLy16P76I6pz2ILcBCIryLNS4816Y 65XbCSWss9UGmSurPQSEtOT4j6davCTgMjYCKc7LJ/dPBGFSp4zJd+wHxUV+0NSAJWZM SL+rsQKIjEeKQaFr6fQ+a3cE9BLsZ5PUP26CIDMWdMfwsyKIwj1rwevpOfTLZYAlw/R+ Ojl+Bp4V+P9QugrXzOWzUF0DcnK8XRNicv3WzF43CJJBA0ixiVOmXiQf0rANF1OTzjiD cuQMHYcu52lVoMJB3L/5DFH2QwLO321q0b/ALK4zu6ZIN3BL27XC0RM4t1OaTlpny8y5 9mQg== X-Forwarded-Encrypted: i=1; AHgh+RqW76LGGRvl1/fWt8+2b8H+qclmLs/kmv43rv/PKmiEjcpygUk6z1GkWdDXatDd6CBuF084vrGDiJF8Dt8=@vger.kernel.org X-Gm-Message-State: AOJu0Yy8zLKeHxMpxtg4BwRnv7KshL91ohpMym1pIgtTV6Tpr0St+VKV h7qXVpzYuoC2Ii2fd6h5X8Chub0mwJ83WvCF4RsCUGTu+9Y3AkxbrTKLj9ZcXXbXmzU= X-Gm-Gg: AR+sD115xbSDS6SmYnXWTW9CnmhcWqASNXa1O0DZ2OKMZm/B4fFE66B/ElWX0ZlztHt 3JflBkcI0Tz0HiK4h9R3HLmXO3Xgdmn02X6s+N8qOhSqM2wPjtCqAd3Yrci89vjVrNcTtGl8XnJ IzR5+rLmkDd+MM7zEX6SOYbgjKCmo4N0YGypH1ebu7V4FkKP84GlWh43DI1DSS1F9lSjwfKKmn7 fXpVzmerGaMajsXM6SigOiuQT41nd2ygZ15YYDkgPg1ZPdfTR/B52e+foZeJqKaYyaUL7FZMO5f 8NLIFDH+AEFSHeDjqN0pilgRBLd+R26l/ynqtLI8CSQxZSyYIdbdbZYNZ/RxfHsJ+J+Mx/gPRqd NtvlIXHxqkhEMA7xVHgSiGwWC3KSLBF1FDOufmC565nzwn2uGxzjKsLYqr4n0x9+E9GWZFP3m+K xXxe9PIv6WJZp8Q34Gea04lk13vaODT2NxbGfVgUFMJsy07qFvnWsxuPer6I1ErKxyIljzka446 83h X-Received: by 2002:a05:622a:5145:b0:516:ed02:c85d with SMTP id d75a77b69052e-52b5666f9c1mr5131111cf.3.1785506819272; Fri, 31 Jul 2026 07:06:59 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id d75a77b69052e-52b4eb956c3sm8318251cf.22.2026.07.31.07.06.58 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 07:06:58 -0700 (PDT) From: David Lee To: steffen.klassert@secunet.com, herbert@gondor.apana.org.au, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: David Lee , Kyle Zeng , Dominik 'Disconnect3d' Czarnota , horms@kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] xfrm: fix compat ALLOCSPI request use-after-free Date: Fri, 31 Jul 2026 14:06:57 +0000 Message-ID: <20260731140658.566571-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request. Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator") Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber Signed-off-by: Kyle Zeng --- Trail of Bits has a reproducer for this bug that triggers a KASAN use-after-free and can share if needed. net/xfrm/xfrm_user.c | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c index d6db63304ba6bd5bbd9c09c665170936e1107ced..a7f35a123648d3946aae88674c7bead5666c9eb3 100644 --- a/net/xfrm/xfrm_user.c +++ b/net/xfrm/xfrm_user.c @@ -1877,7 +1877,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh, struct net *net = sock_net(skb->sk); struct xfrm_state *x; struct xfrm_userspi_info *p; - struct xfrm_translator *xtr; struct sk_buff *resp_skb; xfrm_address_t *daddr; int family; @@ -1943,17 +1942,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh, goto out; } - xtr = xfrm_get_translator(); - if (xtr) { - err = xtr->alloc_compat(skb, nlmsg_hdr(skb)); - - xfrm_put_translator(xtr); - if (err) { - kfree_skb(resp_skb); - goto out; - } - } - err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid); out: -- 2.53.0