From: Chengfeng Ye <nicoyip.dev@gmail.com>
To: David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>, Martin KaFai Lau <kafai@fb.com>,
Wei Wang <weiwan@google.com>
Cc: Hangbin Liu <hangbin.liu@linux.dev>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
Chengfeng Ye <nicoyip.dev@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH net v2] ipv4: Fix device use-after-free in ip_mc_output()
Date: Tue, 29 Sep 2026 00:25:34 +0800 [thread overview]
Message-ID: <20260928162534.2122207-1-nicoyip.dev@gmail.com> (raw)
ip_mc_output() reads rt->dst.dev and stores it in skb->dev without RCU
protection. dst_dev_put() can concurrently replace the destination device
and release the old device after an RCU grace period, leaving the multicast
output path with a stale skb->dev.
The stale device can be dereferenced by the post-routing path. In
particular, a socket using IP_PMTUDISC_PROBE reaches ip_skb_dst_mtu() from
ip_finish_output() and reads the freed device's MTU.
KASAN reported:
BUG: KASAN: slab-use-after-free in ip_skb_dst_mtu+0x634/0x740
Read of size 4 at addr ffff88810921c038 by task poc/98
Call Trace:
ip_skb_dst_mtu+0x634/0x740
__ip_finish_output.part.0+0x22/0x2c0
ip_mc_output+0x287/0x930
ip_send_skb+0x11d/0x150
udp_send_skb+0x63e/0xdf0
udp_sendmsg+0x1235/0x1da0
__sys_sendto+0x32c/0x3a0
Freed by task 99:
kfree+0x131/0x3c0
device_release+0xc8/0x240
kobject_put+0x14d/0x280
netdev_run_todo+0x4cb/0xc70
rtnl_dellink+0x362/0xa90
Protect the whole multicast output path with an RCU read-side critical
section, as ip_output() already does. Load the destination device through
skb_dst_dev_rcu() and keep it protected through the post-routing hooks and
ip_finish_output().
Fixes: 4a6ce2b6f2ec ("net: introduce a new function dst_dev_put()")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
Changes in v2:
- Protect the whole ip_mc_output() path instead of only the MTU read.
- Load the destination device with skb_dst_dev_rcu(), matching ip_output().
- Use the commit that made dst device replacement RCU-protected as Fixes.
Link: https://lore.kernel.org/r/20260927071051.3693368-1-nicoyip.dev@gmail.com/ [v1]
net/ipv4/ip_output.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3..cf44597896cd 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -367,8 +367,11 @@ static int ip_mc_finish_output(struct net *net, struct sock *sk,
int ip_mc_output(struct net *net, struct sock *sk, struct sk_buff *skb)
{
struct rtable *rt = skb_rtable(skb);
- struct net_device *dev = rt->dst.dev;
+ struct net_device *dev;
+ int ret;
+ rcu_read_lock();
+ dev = skb_dst_dev_rcu(skb);
/*
* If the indicated interface is up and running, send the packet.
*/
@@ -406,7 +409,8 @@ int ip_mc_output(struct net *net, struct sock *sk, struct sk_buff *skb)
if (ip_hdr(skb)->ttl == 0) {
kfree_skb(skb);
- return 0;
+ ret = 0;
+ goto out;
}
}
@@ -418,10 +422,13 @@ int ip_mc_output(struct net *net, struct sock *sk, struct sk_buff *skb)
ip_mc_finish_output);
}
- return NF_HOOK_COND(NFPROTO_IPV4, NF_INET_POST_ROUTING,
- net, sk, skb, NULL, skb->dev,
- ip_finish_output,
- !(IPCB(skb)->flags & IPSKB_REROUTED));
+ ret = NF_HOOK_COND(NFPROTO_IPV4, NF_INET_POST_ROUTING,
+ net, sk, skb, NULL, skb->dev,
+ ip_finish_output,
+ !(IPCB(skb)->flags & IPSKB_REROUTED));
+out:
+ rcu_read_unlock();
+ return ret;
}
int ip_output(struct net *net, struct sock *sk, struct sk_buff *skb)
--
2.43.0
next reply other threads:[~2026-09-28 16:25 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:25 Chengfeng Ye [this message]
2026-09-29 8:37 ` [PATCH net v2] ipv4: Fix device use-after-free in ip_mc_output() Antoine Tenart
2026-09-29 9:42 ` Jiayuan Chen
2026-09-29 16:36 ` Ido Schimmel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928162534.2122207-1-nicoyip.dev@gmail.com \
--to=nicoyip.dev@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=hangbin.liu@linux.dev \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kafai@fb.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
--cc=weiwan@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.