netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit()
@ 2024-02-20 10:25 kovalev
  2024-02-20 10:36 ` Pablo Neira Ayuso
  2024-02-22  1:23 ` Jakub Kicinski
  0 siblings, 2 replies; 4+ messages in thread
From: kovalev @ 2024-02-20 10:25 UTC (permalink / raw)
  To: netdev
  Cc: pabeni, davem, edumazet, kuba, jiri, jacob.e.keller, johannes,
	idosch, kovalev, horms, david.lebrun, pablo

From: Vasiliy Kovalev <kovalev@altlinux.org>

The pernet operations structure for the subsystem must be registered
before registering the generic netlink family.

Introduced in commit 134e63756d5f ("genetlink: make netns aware")
Signed-off-by: Vasiliy Kovalev <kovalev@altlinux.org>
---
 net/netlink/genetlink.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/netlink/genetlink.c b/net/netlink/genetlink.c
index 8c7af02f845400..20a7d792dd52ec 100644
--- a/net/netlink/genetlink.c
+++ b/net/netlink/genetlink.c
@@ -1879,14 +1879,14 @@ static int __init genl_init(void)
 {
 	int err;
 
-	err = genl_register_family(&genl_ctrl);
-	if (err < 0)
-		goto problem;
-
 	err = register_pernet_subsys(&genl_pernet_ops);
 	if (err)
 		goto problem;
 
+	err = genl_register_family(&genl_ctrl);
+	if (err < 0)
+		goto problem;
+
 	return 0;
 
 problem:
-- 
2.33.8


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit()
  2024-02-20 10:25 [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit() kovalev
@ 2024-02-20 10:36 ` Pablo Neira Ayuso
  2024-02-20 11:03   ` kovalev
  2024-02-22  1:23 ` Jakub Kicinski
  1 sibling, 1 reply; 4+ messages in thread
From: Pablo Neira Ayuso @ 2024-02-20 10:36 UTC (permalink / raw)
  To: kovalev
  Cc: netdev, pabeni, davem, edumazet, kuba, jiri, jacob.e.keller,
	johannes, idosch, horms, david.lebrun

On Tue, Feb 20, 2024 at 01:25:12PM +0300, kovalev@altlinux.org wrote:
> From: Vasiliy Kovalev <kovalev@altlinux.org>
> 
> The pernet operations structure for the subsystem must be registered
> before registering the generic netlink family.

IIRC, you pointed to a syzbot report on genetlink similar to gtp.

Maybe add that tag here and get the robot to test this fix?

I'd suggest to describe the scenario, which is: There is a race that
allows netlink dump and walking on pernet data while such pernet data
is not yet set up.

Thanks.

> Introduced in commit 134e63756d5f ("genetlink: make netns aware")
> Signed-off-by: Vasiliy Kovalev <kovalev@altlinux.org>
> ---
>  net/netlink/genetlink.c | 8 ++++----
>  1 file changed, 4 insertions(+), 4 deletions(-)
> 
> diff --git a/net/netlink/genetlink.c b/net/netlink/genetlink.c
> index 8c7af02f845400..20a7d792dd52ec 100644
> --- a/net/netlink/genetlink.c
> +++ b/net/netlink/genetlink.c
> @@ -1879,14 +1879,14 @@ static int __init genl_init(void)
>  {
>  	int err;
>  
> -	err = genl_register_family(&genl_ctrl);
> -	if (err < 0)
> -		goto problem;
> -
>  	err = register_pernet_subsys(&genl_pernet_ops);
>  	if (err)
>  		goto problem;
>  
> +	err = genl_register_family(&genl_ctrl);
> +	if (err < 0)
> +		goto problem;
> +
>  	return 0;
>  
>  problem:
> -- 
> 2.33.8
> 

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit()
  2024-02-20 10:36 ` Pablo Neira Ayuso
@ 2024-02-20 11:03   ` kovalev
  0 siblings, 0 replies; 4+ messages in thread
From: kovalev @ 2024-02-20 11:03 UTC (permalink / raw)
  To: Pablo Neira Ayuso
  Cc: netdev, pabeni, davem, edumazet, kuba, jiri, jacob.e.keller,
	johannes, idosch, horms, david.lebrun

Hi Pablo,

20.02.2024 13:36, Pablo Neira Ayuso wrote:
> On Tue, Feb 20, 2024 at 01:25:12PM +0300, kovalev@altlinux.org wrote:
>> From: Vasiliy Kovalev <kovalev@altlinux.org>
>>
>> The pernet operations structure for the subsystem must be registered
>> before registering the generic netlink family.
> IIRC, you pointed to a syzbot report on genetlink similar to gtp.

Yes, I was referring to the link 
https://lore.kernel.org/all/0000000000007549a6060f99544d@google.com/T/ ,

>
> Maybe add that tag here and get the robot to test this fix?
but since the syzbot does not have a reproducer, I cannot say for sure 
that this is exactly the problem that this patch fixes, since syzbot 
refers to the tipc_udp_nl_dump_remoteip function and suddenly there is 
another problem...
>
> I'd suggest to describe the scenario, which is: There is a race that
> allows netlink dump and walking on pernet data while such pernet data
> is not yet set up.
>
> Thanks.

-- 
Regards,
Vasiliy Kovalev


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit()
  2024-02-20 10:25 [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit() kovalev
  2024-02-20 10:36 ` Pablo Neira Ayuso
@ 2024-02-22  1:23 ` Jakub Kicinski
  1 sibling, 0 replies; 4+ messages in thread
From: Jakub Kicinski @ 2024-02-22  1:23 UTC (permalink / raw)
  To: kovalev
  Cc: netdev, pabeni, davem, edumazet, jiri, jacob.e.keller, johannes,
	idosch, horms, david.lebrun, pablo

On Tue, 20 Feb 2024 13:25:12 +0300 kovalev@altlinux.org wrote:
> From: Vasiliy Kovalev <kovalev@altlinux.org>
> 
> The pernet operations structure for the subsystem must be registered
> before registering the generic netlink family.

I think this one is incorrect, genetlink is what other families
register _with_. It's special. Until it opens the socket in
genl_pernet_init() nothing can reach it from user space.

We should probably add a comment saying that it's special, I get
the feeling other families ended up doing a copy & paste of genetlink..
-- 
pw-bot: cr

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2024-02-22  1:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-02-20 10:25 [PATCH net ver.2] genetlink: fix possible use-after-free and null-ptr-deref in genl_dumpit() kovalev
2024-02-20 10:36 ` Pablo Neira Ayuso
2024-02-20 11:03   ` kovalev
2024-02-22  1:23 ` Jakub Kicinski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).