netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats
@ 2022-03-12  0:53 Saeed Mahameed
  2022-03-14 20:08 ` Joe Damato
  2022-03-14 22:10 ` patchwork-bot+netdevbpf
  0 siblings, 2 replies; 3+ messages in thread
From: Saeed Mahameed @ 2022-03-12  0:53 UTC (permalink / raw)
  To: Jakub Kicinski, David S. Miller; +Cc: netdev, Joe Damato, Saeed Mahameed

From: Saeed Mahameed <saeedm@nvidia.com>

We need to sync page pool stats only for active channels. Reading ethtool
stats on a down netdev or a netdev with modified number of channels will
result in a user-after-free, trying to access page pools that are freed
already.

BUG: KASAN: use-after-free in mlx5e_stats_grp_sw_update_stats+0x465/0xf80
Read of size 8 at addr ffff888004835e40 by task ethtool/720

Fixes: cc10e84b2ec3 ("mlx5: add support for page_pool_get_stats")
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Reported-by: Jakub Kicinski <kuba@kernel.org>
---
 drivers/net/ethernet/mellanox/mlx5/core/en_stats.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c b/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
index 336e4d04c5f2..bdc870f9c2f3 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
@@ -521,14 +521,15 @@ static MLX5E_DECLARE_STATS_GRP_OP_UPDATE_STATS(sw)
 
 	memset(s, 0, sizeof(*s));
 
+	for (i = 0; i < priv->channels.num; i++) /* for active channels only */
+		mlx5e_stats_update_stats_rq_page_pool(priv->channels.c[i]);
+
 	for (i = 0; i < priv->stats_nch; i++) {
 		struct mlx5e_channel_stats *channel_stats =
 			priv->channel_stats[i];
 
 		int j;
 
-		mlx5e_stats_update_stats_rq_page_pool(priv->channels.c[i]);
-
 		mlx5e_stats_grp_sw_update_stats_rq_stats(s, &channel_stats->rq);
 		mlx5e_stats_grp_sw_update_stats_xdpsq(s, &channel_stats->rq_xdpsq);
 		mlx5e_stats_grp_sw_update_stats_ch_stats(s, &channel_stats->ch);
-- 
2.35.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats
  2022-03-12  0:53 [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats Saeed Mahameed
@ 2022-03-14 20:08 ` Joe Damato
  2022-03-14 22:10 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: Joe Damato @ 2022-03-14 20:08 UTC (permalink / raw)
  To: Saeed Mahameed; +Cc: Jakub Kicinski, David S. Miller, netdev, Saeed Mahameed

On Fri, Mar 11, 2022 at 04:53:53PM -0800, Saeed Mahameed wrote:
> From: Saeed Mahameed <saeedm@nvidia.com>
> 
> We need to sync page pool stats only for active channels. Reading ethtool
> stats on a down netdev or a netdev with modified number of channels will
> result in a user-after-free, trying to access page pools that are freed
> already.
> 
> BUG: KASAN: use-after-free in mlx5e_stats_grp_sw_update_stats+0x465/0xf80
> Read of size 8 at addr ffff888004835e40 by task ethtool/720
> 
> Fixes: cc10e84b2ec3 ("mlx5: add support for page_pool_get_stats")
> Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
> Reported-by: Jakub Kicinski <kuba@kernel.org>

Err, sorry about that folks - my bad. Thanks for catching that Jakub and
sorry for the trouble Saeed.

LGTM.

Acked-by: Joe Damato <jdamato@fastly.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats
  2022-03-12  0:53 [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats Saeed Mahameed
  2022-03-14 20:08 ` Joe Damato
@ 2022-03-14 22:10 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2022-03-14 22:10 UTC (permalink / raw)
  To: Saeed Mahameed; +Cc: kuba, davem, netdev, jdamato, saeedm

Hello:

This patch was applied to netdev/net-next.git (master)
by Jakub Kicinski <kuba@kernel.org>:

On Fri, 11 Mar 2022 16:53:53 -0800 you wrote:
> From: Saeed Mahameed <saeedm@nvidia.com>
> 
> We need to sync page pool stats only for active channels. Reading ethtool
> stats on a down netdev or a netdev with modified number of channels will
> result in a user-after-free, trying to access page pools that are freed
> already.
> 
> [...]

Here is the summary with links:
  - [net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats
    https://git.kernel.org/netdev/net-next/c/8772cc499bff

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2022-03-14 22:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-03-12  0:53 [PATCH net-next] net/mlx5e: Fix use-after-free in mlx5e_stats_grp_sw_update_stats Saeed Mahameed
2022-03-14 20:08 ` Joe Damato
2022-03-14 22:10 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).