From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f171.google.com (mail-qk1-f171.google.com [209.85.222.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 26A8C2F4A05 for ; Thu, 13 Aug 2026 02:21:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786587674; cv=none; b=T5WxxJO9qi0vhbiZJ2YMoZzzrcyefYXB3KWG112JxdBfluA4a73idSUMrAInr6+trdV5VSuUl7d4HIZjasqSISZn5Q4qAFvq3eacoAtBL78kN4hHrJs4WoxgsrOvTZjZortmI8yblGns5/E7i14VvhrR5d3KsDk/WNjtPAK1A7I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786587674; c=relaxed/simple; bh=uS9sWbpqDY7qVtQkvy/PC8zLLElz8q6kaRjwUGfvU7U=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HX99okhDYvNsuxeog9t04JopjRQ5IQtaFtf38sPKC/qkp/lWtrX45WdeVY8nxg9WPFJEGVsPEyBAwMzHlfWkmUBr28hADgX/U7hGEc43T7+D/21urtP95dEMtCX4aXrt/5QJB+kPPwITouRu1+moATpnBKW1wggIzi0wJKrNBl4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=W0mbpK/j; arc=none smtp.client-ip=209.85.222.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="W0mbpK/j" Received: by mail-qk1-f171.google.com with SMTP id af79cd13be357-92edb12cdf2so126423385a.3 for ; Wed, 12 Aug 2026 19:21:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786587672; x=1787192472; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=OQ0mOHVrQqy6gW071BjekeyZkSroC7y2i96KZ+jhet4=; b=W0mbpK/jaV+KMTfBGpPRzEvB9DAoDlxyne+dQLwMj33MmMBTAktfw5ruGaizfyqutT uHWFya/TUNipk6g6YJK53b20CbKwSdPaqEhK/shsZ07W5/E+6PYzOesFNPQEwFvIgWRU 9mwfV8w00rxf6v2W0i9xOo0ExB9MgUBoR7c3Yer3BWEBN2IP6ZQybui5aOoxmByiD0Wk ErgQtHKu/L58ufbLtWFr3Jedtts9t5UoZ6eJIzOiwzOV5bD8dqiXnjE7O2bwA7Yu2z4O vinWY5seT2zFj89XA58y91SIVmXPCXudJmQPj8uiRdtt6pI3axZ04CVay1QyUHBrMTTh E7pA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786587672; x=1787192472; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=OQ0mOHVrQqy6gW071BjekeyZkSroC7y2i96KZ+jhet4=; b=LSwNsQ7r7VzRKctfn27OTeSpKJVOcT6yULsyTX36G/nVEyFp6LH5/L0s5Fkk/hrujc a1jub3ZgxOVFfoH7j60LDBBX8taJgO2UJOS6uUsNm7ww1nscTEFzIRgijCQyoyRAJbWj Uo814C5trW7y7XQFEbPecgyFgHmlNsPCHcL1Wi9xGe+ZLHw7SK5fKrwr7jU8QK3WUEeZ dkKfcLkQJH5GGQq1dsNKlPtcTPeK2/u7nVPM9uahl176PYNJPD8yx4rQBQbQ/mVIFfW6 CPTnTlRKPbXZk+Gz5gv67DubISLjVWQTH4Rx4TsijWq07xfMc6m45cIpJUafupeN5zgL S+Rg== X-Forwarded-Encrypted: i=1; AHgh+RpNlcyVCC8pl5hoP4D2XUFRcd04botsH8XnkAQ+Yag8qMAz0recWt4icLwsIMS391Kdh7nYtmaWJqaih2g=@vger.kernel.org X-Gm-Message-State: AOJu0YzHvohKuQOpjtc2iJaJn1SW1S9o2SzYnP98hC570LBoWoIt2k12 GtMq17AuShUg8DpAboJRcB5iE0SD5C2LU4K3M/038xDP5oVHKuZrBbkX X-Gm-Gg: AR+sD11srX6E4gvO1DxJ93COHhD1z1T4aZY1ONxEW+FBdhNLWF2kXdhTlsaFx2aL0/0 N2NeHTpMtGY8cK2mmsA9WuGcFIklBni7wAglIby6k0GTKdFMGrZQhdD+iitYvTyA8e33FXI7btA 7zr1yG5eKMrp42eqyROSesjBGeZeWCXwWxzDsOGGKjJJrj4d6wewiMVfGJGGYWSZR7uRWq4rpQy 1txfxYrFqw5TM8wCcnqz5C5gqrKC5yjYOEBNTtXxLbnil7HB/A9JEJLx+F5cywDJaVKbsJ5o8HG O+Cb0WT/BCbc/YMJkGb3SlSQPI9AzlWFllvAyPIFkY0Jzq14yvKsnjWWABoZ0snzfn3z18ZUBKI XYu0Ec9BfRwYeVvbem7QPqRynV4uEb1xZBb6OuvlYsgu75oZvRk5PMOnL7J+OPiCge3y33o/No+ jk4Koun+iLixgHoZKXeopc8DTUCbIrQFQ84ghdQodZEyveXS7rmQPbll4= X-Received: by 2002:a05:620a:479a:b0:936:587d:338c with SMTP id af79cd13be357-936bfb39800mr173250485a.37.1786587671878; Wed, 12 Aug 2026 19:21:11 -0700 (PDT) Received: from beelink.. ([185.217.69.177]) by smtp.gmail.com with ESMTPSA id af79cd13be357-936c1b11d44sm45064185a.22.2026.08.12.19.21.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 19:21:10 -0700 (PDT) From: Aldo Ariel Panzardo To: Jeremy Kerr , Matt Johnston Cc: davem@davemloft.net, Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Aldo Ariel Panzardo Subject: [PATCH] net: mctp: hold a reference to the route device in mctp_route_lookup() Date: Wed, 12 Aug 2026 23:21:02 -0300 Message-ID: <20260813022102.2792032-1-qwe.aldo@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addrs. mctp_dev_saddr() then reads rt->dev->addrs[0], giving a use-after-free reachable by an unprivileged local AF_MCTP user on the receive/forwarding path (no CAP_NET_RAW required): BUG: KASAN: slab-use-after-free in mctp_route_lookup Read of size 1 at addr ... by task mctp_uaf/... mctp_route_lookup mctp_pkttype_receive Freed by task ...: kfree mctp_dev_put mctp_dev_notify In the same window mctp_dst_from_route() -> mctp_dev_hold() also increments a refcount that has already reached zero ("refcount_t: addition on 0 ... mctp_dev_hold"). This reintroduces the use-after-free class of CVE-2023-3439: the source address lookup was moved ahead of the point where the destination takes its device reference. Take a reference with refcount_inc_not_zero() before touching rt->dev, skip a device that is already dead, and drop the reference once the destination has taken its own. Fixes: 22cb45afd221 ("net: mctp: perform source address lookups when we populate our dst") Cc: stable@vger.kernel.org Signed-off-by: Aldo Ariel Panzardo --- A reproducer is available on request. net/mctp/route.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/net/mctp/route.c b/net/mctp/route.c index 1f3dccbb7a..b19c63a569 100644 --- a/net/mctp/route.c +++ b/net/mctp/route.c @@ -998,14 +998,29 @@ int mctp_route_lookup(struct net *net, unsigned int dnet, mtu = mtu ?: rt->mtu; if (rt->dst_type == MCTP_ROUTE_DIRECT) { - mctp_eid_t saddr = mctp_dev_saddr(rt->dev); + mctp_eid_t saddr; + + /* rt->dev may be going away concurrently: its last + * reference is dropped in mctp_dev_put(), which frees + * mdev->addrs that mctp_dev_saddr() reads, and + * mctp_dst_from_route() takes a reference on it. Pin + * it before use, and skip a device that is already + * dead rather than resurrecting it. + */ + if (!refcount_inc_not_zero(&rt->dev->refs)) + break; + + saddr = mctp_dev_saddr(rt->dev); /* cannot do gateway-ed routes without a src */ - if (saddr == MCTP_ADDR_NULL && depth != 0) + if (saddr == MCTP_ADDR_NULL && depth != 0) { + mctp_dev_put(rt->dev); break; + } if (dst) mctp_dst_from_route(dst, daddr, saddr, mtu, rt); + mctp_dev_put(rt->dev); rc = 0; break; -- 2.43.0