From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B743646A5F9 for ; Fri, 31 Jul 2026 16:30:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515403; cv=none; b=X5c/CXCtA9px00C92NUP1NzT3S8U+Y0j9Vp1BOLFFMJJOXLFdYc/BEqO43EyWz+1d0vhD/gX/6BTK0RCvKogYbrQ3JXU751ojBxfuS9h4KO3FtVWEL8Hm6iU9L9AVn1sWn/qHDEgSN11eD2yvKUjOL/bzaXuB+GC0ZtSCuqwieY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515403; c=relaxed/simple; bh=jGDarGoCosi22LNoT8W76BEldiYKRotoaVhCB39/8xo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=d2bnyXPtl5gMMENFK+8/12l7anM6KuHiu6LETXo/E5LzH3JArvBD1FZWYknO9tUXiVNbKnqlPUK4RyoO/4BYVTG6fJbCfb/sdCDiDFdrh5aYt88mv4gJJlGME9wwahT/++dH5yHJtmGkngLVolqzVproUuZS8T5sJYWdJZX6YsU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=q9ZfZfP5; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="q9ZfZfP5" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-3856d4015e0so140075a91.2 for ; Fri, 31 Jul 2026 09:30:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785515401; x=1786120201; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=sZ9QZ52VgaJYmqEYMkc9RIQ8PoagjOPOXOHcuoYV6SE=; b=q9ZfZfP53xqOnBRVO3sopnk6fiHMlFNNHbXnBHBPjxxc8BekzRzh7W9rzwlvl5cL+X bm3z1SALV3dX5gRCWZZv6NCfi4qDFiT0IjJQlX6aNMUv8gUAEalxaXZHDZQR3fCq25Wn S8M6a+l0cKi1GSrcHJylw/MYeSmPf+PJppPE6J7LKj9o5HqQ1i7lz1WqmvhTDi/Fbv8N rl7gnLXR8NW7xv6RgKiYAi9bNUvXdef34HLcGaUNwPvuvWZH2LUBh5S+rVIHuoeSNTuw EQuphtB9hJlFg7Uhv00TtR2TmfOkTLRMGB+wRRbX2yTkMxX2wC81R9OcGHg1ameLNHFG 7LrA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785515401; x=1786120201; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sZ9QZ52VgaJYmqEYMkc9RIQ8PoagjOPOXOHcuoYV6SE=; b=CTYf63v9X40MOZqQ0Xi1ERA+DV2wwt+ETq0ANtF0qcFefaDGk537GTXYYJ8ZxO7DsS UfUYM9sVS4zfDjJsXC4KQG6+VTkH8o5B54ITAHF+SGf/NPzUMqW6CO0uWTMpn0eytLLJ C28o/4Z1CTS/BaVw7UiyzZH53fr2KYSioENJpB3fKpVgH4/IrnJ/+77bHkPg6hPeiGNi c2k16pxVw7sQ/gX39fWVIKRbHvt4dbFJmbQhXChEovXpOvp+w3MALp/Ak7x7cHP64NYh kZ5Dg9IZxdCf/zC4VLmBvSV2sOXQAiSIJHC5/g0u1yFMC+FrfErCcSKQV5kzyvSQKkGd iEjw== X-Forwarded-Encrypted: i=1; AHgh+RpNWV+MQNyXCZCRl37bd3RnSXJW9ycBBldDG+26ZGycH9bEtC0WLIjY7+UThz8CO3+6coEu2cbQ/xUTVIY=@vger.kernel.org X-Gm-Message-State: AOJu0YzhiGo6kQeV5jlZ/gG+XksTPD1ESqSWfu20oGd6rK3wzURKCz59 DoMQLmvuE79vaLPj4HpVQ8YwGNeQlV9pLAmmCcwzsT3KDtgYVDae0dRJ X-Gm-Gg: AR+sD11LtHczkFFvR2UsbiIbrfnNf8BW8O40fukysIr4RlFo3ggwmbEcLGDyf01e9cT ijLSy4YnxBSTAv+SMlJ4tsy2OFecGRUk2IL4a0PlLEh40ngdiuLeaR1Zkv0bI5oZTClK5PgZBKI WKpwI4xQBWtl0/wE1cEiQRd/LxwuB0gOyL2gB3ITORKGSB9lLNGE4bZBcFvR34skpoEM67l5nog HNCDMPeVJ5UmKgQd5PaQjl4WAwYXIrd4h5wbHinqtX9fIe7Xayu2TZPfTxC5o9H6NvnFfceCpo5 e2UrB+K0viEWauIv9nZ7dK9dHKoEE/HiQfRpiX3uYTzBuRYUKZCHH5ICtsroKCFCptsa+L1Um3C u2u9k7LCYg7nezJ4jO3/u62H1zDYDOvudMZsvUCiQ8s+QbmR//t/0AIi5OfXQ92ECWg26dNskq2 Jud9d6HfALl9r/6hzsBrxGfds2AleqdHcUQx5QEHiNPYghVO6e6VYEZURo2kaVj41oHSeskb94m kiGUYiQl5CCfaZbt4zTmDddRYogZhhesyc1+E/NFvpGz0R8B2nv0yJ4cSOcmf5xdGrevxNmCTAg vg== X-Received: by 2002:a17:90b:58c3:b0:38e:ab3f:2c99 with SMTP id 98e67ed59e1d1-38fbc4c673dmr657748a91.2.1785515400659; Fri, 31 Jul 2026 09:30:00 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13fab4fdb80sm4279637c88.15.2026.07.31.09.29.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:29:59 -0700 (PDT) From: Chengfeng Ye To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Stefano Brivio , Sabrina Dubroca Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH net] ipv4: fix use-after-free in fib_nhc_update_mtu() Date: Sat, 1 Aug 2026 00:29:38 +0800 Message-ID: <20260731162938.3388534-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit fib_nhc_update_mtu() walks the nexthop exception table under RTNL, but RTNL does not serialize this walk with PMTU exception updates. The walk uses rcu_dereference_protected() with a constant true condition without holding either fnhe_lock or an RCU read-side critical section. The following interleaving can therefore occur: CPU 0 CPU 1 fib_nhc_update_mtu() update_or_create_fnhe() load fnhe spin_lock_bh(&fnhe_lock) fnhe_remove_oldest() unlink fnhe kfree_rcu(fnhe, rcu) access fnhe after grace period KASAN reported: BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410 Read of size 8 at addr ffff888107d49000 by task poc/90 Call Trace: fib_nhc_update_mtu+0x3df/0x410 fib_sync_mtu+0x7a/0xd0 fib_netdev_event+0x229/0x3f0 netif_set_mtu_ext+0x33a/0x570 dev_set_mtu+0x88/0x120 Allocated by task 89: update_or_create_fnhe+0xa80/0x1110 __ip_rt_update_pmtu+0x8f2/0xcd0 ipv4_sk_update_pmtu+0x49e/0x690 udp_err+0xd92/0x1080 Freed by task 0: __kasan_slab_free+0x43/0x70 kvfree_rcu_cb+0x12f/0x420 rcu_core+0x509/0x18e0 Protect the full walk with rcu_read_lock() and use rcu_dereference() for the RCU-published pointers. This prevents reclaim from completing until all references held by the walk have been dropped, without serializing PMTU updates against the entire hash-table traversal. Fixes: af7d6cce5369 ("net: ipv4: update fnhe_pmtu when first hop's MTU changes") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/ipv4/fib_semantics.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/net/ipv4/fib_semantics.c b/net/ipv4/fib_semantics.c index 4f3c0740dde9..6ecc6654427c 100644 --- a/net/ipv4/fib_semantics.c +++ b/net/ipv4/fib_semantics.c @@ -1879,16 +1879,17 @@ void fib_nhc_update_mtu(struct fib_nh_common *nhc, u32 new, u32 orig) struct fnhe_hash_bucket *bucket; int i; - bucket = rcu_dereference_protected(nhc->nhc_exceptions, 1); + rcu_read_lock(); + bucket = rcu_dereference(nhc->nhc_exceptions); if (!bucket) - return; + goto out; for (i = 0; i < FNHE_HASH_SIZE; i++) { struct fib_nh_exception *fnhe; - for (fnhe = rcu_dereference_protected(bucket[i].chain, 1); + for (fnhe = rcu_dereference(bucket[i].chain); fnhe; - fnhe = rcu_dereference_protected(fnhe->fnhe_next, 1)) { + fnhe = rcu_dereference(fnhe->fnhe_next)) { if (fnhe->fnhe_mtu_locked) { if (new <= fnhe->fnhe_pmtu) { fnhe->fnhe_pmtu = new; @@ -1900,6 +1901,8 @@ void fib_nhc_update_mtu(struct fib_nh_common *nhc, u32 new, u32 orig) } } } +out: + rcu_read_unlock(); } void fib_sync_mtu(struct net_device *dev, u32 orig_mtu) -- 2.43.0