All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot ci <syzbot+ci11ed5d32bbe502f8@syzkaller.appspotmail.com>
To: fw@strlen.de, kadlec@netfilter.org, netfilter-devel@vger.kernel.org
Cc: syzbot@lists.linux.dev, syzkaller-bugs@googlegroups.com
Subject: [syzbot ci] Re: netfilter: switch ipset to rhashtable
Date: Thu, 06 Aug 2026 08:22:21 -0700	[thread overview]
Message-ID: <6a74a6ad.ec7c9571.3ac9bb.0053.GAE@google.com> (raw)
In-Reply-To: <20260806101947.2802-1-fw@strlen.de>

syzbot ci has tested the following series

[v1] netfilter: switch ipset to rhashtable
https://lore.kernel.org/all/20260806101947.2802-1-fw@strlen.de
* [PATCH nf 1/7] netfilter: ipset: remove need to allocate memory on delete operations
* [PATCH nf 2/7] netfilter: ipset: let destroy callbacks adjust ext mem size
* [PATCH nf 3/7] netfilter: ipset: add rhashtable boilerplate stubs
* [PATCH nf 4/7] netfilter: ipset: add rhltable boilerplate stubs
* [PATCH nf 5/7] netfilter: ipset: replace internal hash table with rhashtable
* [PATCH nf 6/7] netfilter: ipset: re-add forceadd support for rhashtable
* [PATCH nf 7/7] netfilter: ipset: also report mem size for cidr storage to userspace

and found the following issues:
* UBSAN: shift-out-of-bounds in hash_netiface6_head
* UBSAN: shift-out-of-bounds in hash_netportnet6_head

Full report is available here:
https://ci.syzbot.org/series/e7969a90-d2b3-4da4-8795-4c3794dae0f0

***

UBSAN: shift-out-of-bounds in hash_netiface6_head

tree:      nf
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/netfilter/nf.git
base:      44871eadd07a7f004aa00cb87399461eea08c630
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/81d26051-7806-406c-9355-fbf52dca8f68/config
syz repro: https://ci.syzbot.org/findings/cb9f585e-5753-41c6-b732-20d1d77f5564/syz_repro

------------[ cut here ]------------
UBSAN: shift-out-of-bounds in net/netfilter/ipset/ip_set_hash_gen.h:1120:46
shift exponent 32 is too large for 32-bit type 'u32' (aka 'unsigned int')
CPU: 1 UID: 0 PID: 5865 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
 __ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
 hash_netiface6_head+0x89e/0x970 net/netfilter/ipset/ip_set_hash_gen.h:1120
 ip_set_dump_do+0x1476/0x1920 net/netfilter/ipset/ip_set_core.c:1664
 netlink_dump+0x711/0xee0 net/netlink/af_netlink.c:2331
 __netlink_dump_start+0x589/0x7b0 net/netlink/af_netlink.c:2446
 netlink_dump_start include/linux/netlink.h:341 [inline]
 ip_set_dump+0x15b/0x1f0 net/netfilter/ipset/ip_set_core.c:1730
 nfnetlink_rcv_msg+0xcc2/0x12b0 net/netfilter/nfnetlink.c:300
 netlink_rcv_skb+0x226/0x4a0 net/netlink/af_netlink.c:2556
 nfnetlink_rcv+0x2b9/0x28c0 net/netfilter/nfnetlink.c:667
 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
 netlink_unicast+0x7bb/0x940 net/netlink/af_netlink.c:1345
 netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1900
 sock_sendmsg_nosec+0x13a/0x180 net/socket.c:775
 __sock_sendmsg net/socket.c:790 [inline]
 ____sys_sendmsg+0x54e/0x850 net/socket.c:2684
 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2738
 __sys_sendmsg net/socket.c:2770 [inline]
 __do_sys_sendmsg net/socket.c:2775 [inline]
 __se_sys_sendmsg net/socket.c:2773 [inline]
 __x64_sys_sendmsg+0x1b1/0x290 net/socket.c:2773
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f7b3159e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f7b323e2028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f7b31825fa0 RCX: 00007f7b3159e019
RDX: 0000000000008080 RSI: 0000200000000180 RDI: 0000000000000004
RBP: 00007f7b3163500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f7b31826038 R14: 00007f7b31825fa0 R15: 00007ffdc35054d8
 </TASK>
---[ end trace ]---


***

UBSAN: shift-out-of-bounds in hash_netportnet6_head

tree:      nf
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/netfilter/nf.git
base:      44871eadd07a7f004aa00cb87399461eea08c630
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/81d26051-7806-406c-9355-fbf52dca8f68/config
syz repro: https://ci.syzbot.org/findings/0f098de1-ac6a-4b30-8a0d-ea1586a67851/syz_repro

------------[ cut here ]------------
UBSAN: shift-out-of-bounds in net/netfilter/ipset/ip_set_hash_gen.h:1120:46
shift exponent 32 is too large for 32-bit type 'u32' (aka 'unsigned int')
CPU: 1 UID: 0 PID: 5838 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
 __ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
 hash_netportnet6_head+0x97a/0xa40 net/netfilter/ipset/ip_set_hash_gen.h:1120
 ip_set_dump_do+0x1476/0x1920 net/netfilter/ipset/ip_set_core.c:1664
 netlink_dump+0x711/0xee0 net/netlink/af_netlink.c:2331
 __netlink_dump_start+0x589/0x7b0 net/netlink/af_netlink.c:2446
 netlink_dump_start include/linux/netlink.h:341 [inline]
 ip_set_dump+0x15b/0x1f0 net/netfilter/ipset/ip_set_core.c:1730
 nfnetlink_rcv_msg+0xcc2/0x12b0 net/netfilter/nfnetlink.c:300
 netlink_rcv_skb+0x226/0x4a0 net/netlink/af_netlink.c:2556
 nfnetlink_rcv+0x2b9/0x28c0 net/netfilter/nfnetlink.c:667
 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
 netlink_unicast+0x7bb/0x940 net/netlink/af_netlink.c:1345
 netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1900
 sock_sendmsg_nosec+0x13a/0x180 net/socket.c:775
 __sock_sendmsg net/socket.c:790 [inline]
 ____sys_sendmsg+0x54e/0x850 net/socket.c:2684
 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2738
 __sys_sendmsg net/socket.c:2770 [inline]
 __do_sys_sendmsg net/socket.c:2775 [inline]
 __se_sys_sendmsg net/socket.c:2773 [inline]
 __x64_sys_sendmsg+0x1b1/0x290 net/socket.c:2773
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f44dc59e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f44dd41d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f44dc825fa0 RCX: 00007f44dc59e019
RDX: 0000000000000000 RSI: 0000200000000200 RDI: 0000000000000004
RBP: 00007f44dc63500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f44dc826038 R14: 00007f44dc825fa0 R15: 00007ffdbc9c05c8
 </TASK>
---[ end trace ]---


***

If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
  Tested-by: syzbot@syzkaller.appspotmail.com

---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.

To test a patch for this bug, please reply with `#syz test`
(should be on a separate line).

The patch should be attached to the email.
Note: arguments like custom git repos and branches are not supported.

      parent reply	other threads:[~2026-08-06 15:22 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 10:19 [PATCH nf 0/7] netfilter: switch ipset to rhashtable Florian Westphal
2026-08-06 10:19 ` [PATCH nf 1/7] netfilter: ipset: remove need to allocate memory on delete operations Florian Westphal
2026-08-09 12:56   ` Jozsef Kadlecsik
2026-08-09 14:14     ` Florian Westphal
2026-08-06 10:19 ` [PATCH nf 2/7] netfilter: ipset: let destroy callbacks adjust ext mem size Florian Westphal
2026-08-06 10:19 ` [PATCH nf 3/7] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-08-06 10:19 ` [PATCH nf 4/7] netfilter: ipset: add rhltable " Florian Westphal
2026-08-06 10:19 ` [PATCH nf 5/7] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-08-06 10:19 ` [PATCH nf 6/7] netfilter: ipset: re-add forceadd support for rhashtable Florian Westphal
2026-08-06 10:19 ` [PATCH nf 7/7] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-08-06 15:22 ` syzbot ci [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a74a6ad.ec7c9571.3ac9bb.0053.GAE@google.com \
    --to=syzbot+ci11ed5d32bbe502f8@syzkaller.appspotmail.com \
    --cc=fw@strlen.de \
    --cc=kadlec@netfilter.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.