* "Kernel Warn in af_inet" in Linux Kernel Version 2.6.26
@ 2024-12-02 4:30 cheung wall
2024-12-02 10:04 ` Eric Dumazet
0 siblings, 1 reply; 2+ messages in thread
From: cheung wall @ 2024-12-02 4:30 UTC (permalink / raw)
To: David S. Miller, Alexey Kuznetsov, pekkas, jmorris, yoshfuji,
kaber
Cc: netdev, linux-kernel
Hello,
I am writing to report a potential vulnerability identified in the
Linux Kernel version 2.6.26.
This issue was discovered using our custom vulnerability discovery
tool.
Affected File:
File: net/ipv4/af_inet.c
Detailed call trace:
[ 1788.473836] KERNEL: assertion (!atomic_read(&sk->sk_wmem_alloc))
failed at net/ipv4/af_inet.c (155)
[ 1788.473836] KERNEL: assertion (!sk->sk_wmem_queued) failed at
net/ipv4/af_inet.c (156)
[ 1788.473836] KERNEL: assertion (!sk->sk_forward_alloc) failed at
net/ipv4/af_inet.c (157)
[ 1788.473836] KERNEL: assertion (!atomic_read(&sk->sk_wmem_alloc))
failed at net/ipv4/af_inet.c (155)
[ 1788.473836] KERNEL: assertion (!sk->sk_wmem_queued) failed at
net/ipv4/af_inet.c (156)
[ 1788.473862] KERNEL: assertion (!sk->sk_forward_alloc) failed at
net/ipv4/af_inet.c (157)
Repro C Source Code: https://pastebin.com/qs5y6Bcy
Root Cause:
The root cause of this bug lies in the improper handling of socket
write memory management in the IPv4 stack, specifically in the
assertions within net/ipv4/af_inet.c. The PoC triggers a sequence of
socket operations, including socket, sendto, listen, and accept, with
crafted input data and parameters. These operations result in
inconsistent states of the sock structure, where critical fields like
sk_wmem_alloc, sk_wmem_queued, and sk_forward_alloc are not properly
cleared or synchronized. The kernel fails to maintain the expected
invariants for these fields, leading to assertion failures that
indicate a logical inconsistency in memory allocation or deallocation
for socket operations. This issue highlights a potential lack of
proper cleanup or state transition checks in the network stack.
Thank you for your time and attention.
Best regards
Wall
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: "Kernel Warn in af_inet" in Linux Kernel Version 2.6.26
2024-12-02 4:30 "Kernel Warn in af_inet" in Linux Kernel Version 2.6.26 cheung wall
@ 2024-12-02 10:04 ` Eric Dumazet
0 siblings, 0 replies; 2+ messages in thread
From: Eric Dumazet @ 2024-12-02 10:04 UTC (permalink / raw)
To: cheung wall, David S. Miller, Alexey Kuznetsov, pekkas, jmorris,
yoshfuji, kaber
Cc: netdev, linux-kernel
On 12/2/24 5:30 AM, cheung wall wrote:
> Hello,
>
> I am writing to report a potential vulnerability identified in the
> Linux Kernel version 2.6.26.
> This issue was discovered using our custom vulnerability discovery
> tool.
>
> Affected File:
>
> File: net/ipv4/af_inet.c
>
> Detailed call trace:
>
> [ 1788.473836] KERNEL: assertion (!atomic_read(&sk->sk_wmem_alloc))
> failed at net/ipv4/af_inet.c (155)
> [ 1788.473836] KERNEL: assertion (!sk->sk_wmem_queued) failed at
> net/ipv4/af_inet.c (156)
> [ 1788.473836] KERNEL: assertion (!sk->sk_forward_alloc) failed at
> net/ipv4/af_inet.c (157)
> [ 1788.473836] KERNEL: assertion (!atomic_read(&sk->sk_wmem_alloc))
> failed at net/ipv4/af_inet.c (155)
> [ 1788.473836] KERNEL: assertion (!sk->sk_wmem_queued) failed at
> net/ipv4/af_inet.c (156)
> [ 1788.473862] KERNEL: assertion (!sk->sk_forward_alloc) failed at
> net/ipv4/af_inet.c (157)
>
> Repro C Source Code: https://pastebin.com/qs5y6Bcy
>
> Root Cause:
>
> The root cause of this bug lies in the improper handling of socket
> write memory management in the IPv4 stack, specifically in the
> assertions within net/ipv4/af_inet.c. The PoC triggers a sequence of
> socket operations, including socket, sendto, listen, and accept, with
> crafted input data and parameters. These operations result in
> inconsistent states of the sock structure, where critical fields like
> sk_wmem_alloc, sk_wmem_queued, and sk_forward_alloc are not properly
> cleared or synchronized. The kernel fails to maintain the expected
> invariants for these fields, leading to assertion failures that
> indicate a logical inconsistency in memory allocation or deallocation
> for socket operations. This issue highlights a potential lack of
> proper cleanup or state transition checks in the network stack.
Please do not fuzz old and not supported kernels.
Or do not report to us the issues, _unless_ they also trigger on
recent/supported kernels.
Thank you.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2024-12-02 10:04 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-12-02 4:30 "Kernel Warn in af_inet" in Linux Kernel Version 2.6.26 cheung wall
2024-12-02 10:04 ` Eric Dumazet
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox