From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2324E51C348; Wed, 30 Sep 2026 17:42:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790160; cv=none; b=N+c4mm+IXLmRAA0yPJSW97uRep++sVfbffvRtHEIPWRCGyH1LVpkYNPB2NrzoNyfsfXxbE4Wsj5CbbY+nRjNA1jxLSFsgi3ClFJ5bT9RStjidyc+NyDCH59yNPnF8pgUWozeluumNhM9Mg/CaM1tqfcKY+3U4VnjG3LVgdcQJ34= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790160; c=relaxed/simple; bh=ueA0pdNbf3YNjR5jt2kvDCAntk5QXv3bKxUErtO/xpc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RN7lRt7SyxmLgSaXgeQsUBXElz2q+3BRoBBTl5/2Em/fa8uCtgh28m9GNtA1RP/XQw1CQ7XcMILeh6OoexZVunNzPwGur9Xkw1pFNVM6n2q6t19vvFr+pI7ruw1xNGx1Si9UkRmCyNG1joLnDV0fiHTa787tzu9tUqu0wugkTKI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TbvRzZn2; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TbvRzZn2" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7BF161F000FF; Wed, 30 Sep 2026 17:42:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790790159; bh=zffBLY31FnFNq9p9NDPmY4vS1LMMimISCocsPI9gn7I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TbvRzZn2Xt3wEbmfY3LXzhf3dYcojdcZri9yVC3DrzkdfBtxieJlcd1IetNpHJO6O 72y6KUK3KLbGMKKsuGzuyta+29dO7/8fPCvEzw5YJmMfRkj868zztG/k4tAcK9Mmwx ysy2LbnnxyMy8tVlZfb68flVk3Pe8K+o5z8xEPrQ= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, XingWang Xiang , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.12 729/877] genetlink: pin family module during policy dump Date: Wed, 30 Sep 2026 17:27:20 +0200 Message-ID: <20260930152430.419238785@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: XingWang Xiang [ Upstream commit 6a1094c34d176827b2b173e163dcc964a13af93f ] The generic netlink controller's policy dump keeps pointers to the target family's operation and policy tables in its callback state. A dump may be split across multiple skbs and remain pending after the initial request. Netlink pins the module which owns the dump callback, but in this case that is the controller's owner rather than the target family's owner. The target family can consequently be unregistered and its module unloaded while a policy dump is pending. Advancing the dump then dereferences policy memory from the unloaded module. Take a reference to the target family's module when the dump starts. Drop it from the error and done paths. This matches the lifetime for which the dump context retains the family and policy pointers. Fixes: d07dcf9aadd6 ("netlink: add infrastructure to expose policies to userspace") Cc: stable@vger.kernel.org Signed-off-by: XingWang Xiang Link: https://patch.msgid.link/20260902084317.4092542-1-v3rdant.xiang@gmail.com Signed-off-by: Jakub Kicinski [ Adjusted context to retain kmalloc(sizeof(*ctx->op_iter), GFP_KERNEL) instead of kmalloc_obj(*ctx->op_iter). ] Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- net/netlink/genetlink.c | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) --- a/net/netlink/genetlink.c +++ b/net/netlink/genetlink.c @@ -1514,6 +1514,7 @@ struct ctrl_dump_policy_ctx { struct netlink_policy_dump_state *state; const struct genl_family *rt; struct genl_op_iter *op_iter; + struct module *owner; u32 op; u16 fam_id; u8 dump_map:1, @@ -1556,6 +1557,9 @@ static int ctrl_dumppolicy_start(struct return -ENOENT; ctx->rt = rt; + ctx->owner = rt->module; + if (!try_module_get(ctx->owner)) + return -ENOENT; if (tb[CTRL_ATTR_OP]) { struct genl_split_ops doit, dump; @@ -1566,7 +1570,7 @@ static int ctrl_dumppolicy_start(struct err = genl_get_cmd_both(ctx->op, rt, &doit, &dump); if (err) { NL_SET_BAD_ATTR(cb->extack, tb[CTRL_ATTR_OP]); - return err; + goto err_put_owner; } if (doit.policy) { @@ -1584,16 +1588,20 @@ static int ctrl_dumppolicy_start(struct goto err_free_state; } - if (!ctx->state) - return -ENODATA; + if (!ctx->state) { + err = -ENODATA; + goto err_put_owner; + } ctx->dump_map = 1; return 0; } ctx->op_iter = kmalloc(sizeof(*ctx->op_iter), GFP_KERNEL); - if (!ctx->op_iter) - return -ENOMEM; + if (!ctx->op_iter) { + err = -ENOMEM; + goto err_put_owner; + } genl_op_iter_init(rt, ctx->op_iter); ctx->dump_map = genl_op_iter_next(ctx->op_iter); @@ -1625,6 +1633,8 @@ err_free_state: netlink_policy_dump_free(ctx->state); err_free_op_iter: kfree(ctx->op_iter); +err_put_owner: + module_put(ctx->owner); return err; } @@ -1763,6 +1773,7 @@ static int ctrl_dumppolicy_done(struct n kfree(ctx->op_iter); netlink_policy_dump_free(ctx->state); + module_put(ctx->owner); return 0; }