From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f52.google.com (mail-qv1-f52.google.com [209.85.219.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7CFE13F58E5 for ; Mon, 10 Aug 2026 14:41:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786372880; cv=none; b=HbkkIjvIsP+ndHYZLf1YyktKr2yBZyejjTMS6neEWwIxQ6IAOCY92oez3AhyaoJhxLWic6Mb9hH2/mlBsoar5HDQ05TGMgIM+D/E1vzmLjUTOM+UAUkTdcJfm+imB6GpUAR2iWyMawnw/atvpjX/VBTHq5dkb6VBX4HD+pEXYR8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786372880; c=relaxed/simple; bh=NT4hmTQV7asOzfynA9Axntikhqqvbc1Sr29Lb2gduPQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=amhHvcVYiLsB+EAHJ5/nbhxoyPQJuAMiNKb/eYJYmOz+Dgep1rQjraN55MO9pg3q8Sc6MD4Cxl9POEIC/HgEZzbzdQ2q2Zpf2TwoCdfQnGzxnJf1FF+O8ygGlHcBHT5bMlx51Kr/ya/XtikOhtg79n9dZBhetVHhHoZo53j9EU0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=XxsoWo6I; arc=none smtp.client-ip=209.85.219.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="XxsoWo6I" Received: by mail-qv1-f52.google.com with SMTP id 6a1803df08f44-9087fb771d3so9221366d6.0 for ; Mon, 10 Aug 2026 07:41:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1786372877; x=1786977677; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=zF8J7vucF9ejv5mC84LVI8cP3TWHPkQougefaqK2FnM=; b=XxsoWo6IbNXsRnCzr/jOsexPMUwAcGetoB/V+HOE6Dtq0CkPgMKlmQd9TLVBCDWLVV ixPKvsKftjC1vaF0Pm8s1HebN3Dl6eDoGJL2qkd8CR1ehQFVrH3GAh0bZfHOUGbkFkie 2YKPYLOloTD8+BaGR9Vzd0bL9Kug8U23iIm6DmKhxGmq4618QWUCMqSNZG3GJa/WYZsm VaTbS0MVaKtIQYastOD/QxvlwXbEuMU8pJz3g0Iy+q8pdNV/ndJn6UFN68QplrEBUeXB 9QV4b0xVNeKmT6i/s9+oVDtp6jevW3o0dt1kl+w/oyeC4hFEGb9Em0dAbqKHFoKEj8XE m75g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786372877; x=1786977677; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zF8J7vucF9ejv5mC84LVI8cP3TWHPkQougefaqK2FnM=; b=ZNAPCoi0l3q0GD+TIV4UoT+YvLQBNaguEn9x2MQzg5Nq8GHV8hwU7JfmbJrWAWkJ6F wHXFQ/lpOnLWvbJ7zW/0gkOEgyc6xezYVuuZ1p/Eq9+wdt7FqznvFDQs8SuHHjJNBXPi Bhg9tR+z8dpCmErvrVfdW7aVhEBuA1vuli3lWC46wDmFeqFsfMpBCezdN2KwMIQ7Hza8 POvnabVBIR1qkYHMeIdUA/v4tVYMlblJVAEG2U0SVIGiL0mXlZ7R1O1aerEOCpUMzZ/3 reY0lfK67o5Vs20fOtioqAz4sKJm4E4fHki2Ywq9pGbxtdwgnxqF2LH7kbzeerb7OIbw D5Jg== X-Forwarded-Encrypted: i=1; AHgh+RowI1DVNI8jjqpGA4hjNG+u/U/9O+c5qLdxPfANpKYUOyHjjaevnuowmtUxk+csj3qiBrs8YUVuXgJ7Auw=@vger.kernel.org X-Gm-Message-State: AOJu0Yy3H+vxtWmZQdaneY98RfWXwGX994oBe4yHlxhHPSi4dXq/kWgv pV1BDoNY2mj9ffHSZg5QsrsqtNfrBbglKp4kx9/qSHykGI5kvJKLXENbj64gkiXxedQ= X-Gm-Gg: AR+sD10Nd1amNpgczJmesKK3wb/0lP7K66xc5i45vcLsqBDsvL0M3w7Uu2610OTHE50 LeM+ALhopSEa+/sHpq7uYh30SQnevGolvGs6i1yM1DVCUN4Uat2b3fmItv5aLTIMQMlbJSriZhI /bIebLeM/dOIr8glsy0WAcyAd6u01eRefEjJ/LRt6A8L6ZqGGUxKeKz9ju+CQNFv8xR6QAYOukw cGGO56M8/H2BoR36mQIul/eTvu5T9rUUPnF4rHMj7A86Pb5q4LECduOEffNpdVLMCHeKJlg6Xec ZdHBgCcZdEJnUZW3vP3jaFJLOQ2w3zns9zguNGC1IqV4Xg3Ak/C0FVLZN9t1/oUX9RCbcBSbLv7 I5jKq80UNeJr5GcsHgdTKng3cPQtN8mxfLtPU/ntN9lROB14LhIkSTa/hli6PAuNSlco+2jg9DO EmwkEuK6b9KjmyGszGC/a91oZo42aUAtFslwO6jfBRnQ3VhPzmtQAXRkPLQLHCaPvB/g== X-Received: by 2002:a05:6214:4709:b0:908:949c:43a6 with SMTP id 6a1803df08f44-908949c4882mr384537146d6.6.1786372877154; Mon, 10 Aug 2026 07:41:17 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908a932a417sm73682786d6.37.2026.08.10.07.41.16 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 10 Aug 2026 07:41:16 -0700 (PDT) From: David Lee To: andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , Sven Eckelmann , Petr Machata , Amit Cohen , Ido Schimmel , Kuniyuki Iwashima , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Lee Subject: [PATCH net v3] vxlan: keep the last remote linked during FDB flush Date: Mon, 10 Aug 2026 14:41:14 +0000 Message-ID: <20260810144115.821654-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Kyle Zeng A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures. Fixes: c499fccb71cb ("vxlan: vxlan_core: Support FDB flushing by destination VNI") Cc: stable@vger.kernel.org Suggested-by: Ido Schimmel Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber Signed-off-by: Kyle Zeng Co-developed-by: David Lee Signed-off-by: David Lee --- Changes in v3: - Remove remotes_flushed and the redundant final p_destroy_fdb assignment, as suggested by Ido Schimmel; the caller initializes the flag to false. Changes in v2: - Add the net tree prefix to the subject. - Restore Kyle Zeng as the patch author and correct the sign-off chain. - Move the research credit below the commit-message separator. - Add the recipients reported by netdev CI. v1: https://lore.kernel.org/all/20260731141311.570187-1-david.lee@trailofbits.com/ Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Trail of Bits has a reproducer for this bug that triggers a KASAN slab-out-of-bounds read in vxlan_snoop() and can share if needed. drivers/net/vxlan/vxlan_core.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c index d834a4865..0c42cfd96 100644 --- a/drivers/net/vxlan/vxlan_core.c +++ b/drivers/net/vxlan/vxlan_core.c @@ -3051,18 +3051,19 @@ vxlan_fdb_flush_match_remotes(struct vxlan_fdb *f, struct vxlan_dev *vxlan, const struct vxlan_fdb_flush_desc *desc, bool *p_destroy_fdb) { - bool remotes_flushed = false; struct vxlan_rdst *rd, *tmp; list_for_each_entry_safe(rd, tmp, &f->remotes, list) { if (!vxlan_fdb_flush_remote_matches(desc, rd)) continue; + if (list_is_singular(&f->remotes)) { + *p_destroy_fdb = true; + return; + } + vxlan_fdb_dst_destroy(vxlan, f, rd, true); - remotes_flushed = true; } - - *p_destroy_fdb = remotes_flushed && list_empty(&f->remotes); } /* Purge the forwarding table */ -- 2.53.0