All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steffen Klassert <steffen.klassert@secunet.com>
To: Zhiling Zou <zhilinz@nebusec.ai>
Cc: <netdev@vger.kernel.org>, <herbert@gondor.apana.org.au>,
	<davem@davemloft.net>, <edumazet@google.com>, <pabeni@redhat.com>,
	<horms@kernel.org>, <vega@nebusec.ai>
Subject: Re: [PATCH net v4 1/1] xfrm: save input state data before secpath resets
Date: Thu, 3 Sep 2026 09:36:51 +0200	[thread overview]
Message-ID: <apkjkwIE5g0MhknV@secunet.com> (raw)
In-Reply-To: <52e0da6a8ae00868e180484645dee769402ee5f0.1787994112.git.zhilinz@nebusec.ai>

On Sat, Aug 29, 2026 at 05:24:24PM +0800, Zhiling Zou wrote:
> xfrm_input() stores the current xfrm_state in the skb secpath while it
> continues receive-side processing. Some input paths can reset that secpath
> before xfrm_input() has finished dereferencing the state.
> 
> Receive callback users such as VTI and XFRM interfaces can reset the
> secpath. The VTI receive path does so before checking whether the packet
> crosses network namespaces, while the XFRM interface path does so only for
> cross-network-namespace packets. The XFRM_MAX_DEPTH error path can also
> reset the secpath before the final drop callback reports the current
> state's protocol.
> 
> If secpath_reset() drops the last state reference while the state is
> concurrently deleted, xfrm_input() can still dereference the freed state
> when selecting transport_finish() or reporting the drop callback protocol.
> 
> Save the state protocol on the stack while the state is still valid,
> and use the already saved address family for transport_finish(). A larval
> XFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This
> preserves the existing drop-path fallback while avoiding the post-reset
> state dereferences without adding an extra state reference to every
> received packet.
> 
> Fixes: df3893c176e9 ("vti: Update the ipv4 side to use it's own receive hook.")
> Cc: stable@vger.kernel.org
> Reported-by: Vega <vega@nebusec.ai>
> Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>

Patch applied, thanks a lot!

      reply	other threads:[~2026-09-03  7:36 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-29  9:24 [PATCH net v4 0/1] xfrm: save input state data before secpath resets Zhiling Zou
2026-08-29  9:24 ` [PATCH net v4 1/1] " Zhiling Zou
2026-09-03  7:36   ` Steffen Klassert [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apkjkwIE5g0MhknV@secunet.com \
    --to=steffen.klassert@secunet.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=horms@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=vega@nebusec.ai \
    --cc=zhilinz@nebusec.ai \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.