From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E563839021F for ; Tue, 4 Aug 2026 05:29:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.179 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785821374; cv=none; b=GjO9ric4gWFBM8duEbr1SmS2PqPAbqz5AMR+9prnKdoVdVn3Lc3z3SttQZyjWISC/WpzhJZwH/Hv7Pem2b0lgK1o+91Yh+HJE1p7/Eew6uyQIgxSFdywY7KndSRffeYX1qXA0rSGd8QBYOOQEyQKRCoxTEjo4uIeKpT67ulD0EU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785821374; c=relaxed/simple; bh=99I9WI10yhgdycaYQdOR7KxDqwzWqjCnddeIITPX87Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PSKMfCYVzTARGYRYgEiNhBl2l3/f8o+kDN4mTPGpbmpPjHxCcRP5Pb2zHv/KMYc4oNi8EPFxpEqLRmIUTrzls2vQkVVOUc83ae1Zk4kvt43A7bHBI9kpvtTJAn1zKwMe8NoQW/GuVErS1TW9umTsmkF1deVIfnkT4M1m6A2IwCc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XeKobOYt; arc=none smtp.client-ip=209.85.214.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XeKobOYt" Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-2ccf2360620so37197255ad.3 for ; Mon, 03 Aug 2026 22:29:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785821372; x=1786426172; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RhvTHN2T2zF1L4JuI+XVqt6JmwKsZDHz84ZkqvimYzA=; b=XeKobOYtTH+RHrJuJq0oYPSPcNEoORZrP24bovlOHSXGTiMI/LcpsCa9xJ6i+Fy+UO SRsJwTi2IuFatNYh4urOnCg/OtzSip0TI7xcZL7MDB+mkIfQh9IiIQBNeTDeQj91+Ld1 7yD6jEHwwGXjYtVqmXkBcp5vUSnal5Zew92bvgchclE4F1wjngs1/5QrpIoSdaGvPKBR a/XUyhYB0V9a881h5dzBvcNDdbgHoz/cXrv0Qln8066+Ir0KVsf8/6XGaMuhvjvriBzU oseLj+OtJnoGAFooMJyKHLbehVS1SWOqy75PlbTGQBWBwx9u9rpQ2P3v2IEzEGOKxho5 EpsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785821372; x=1786426172; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=RhvTHN2T2zF1L4JuI+XVqt6JmwKsZDHz84ZkqvimYzA=; b=iyBObEF5L5roJbtch/Jl5aeBrOxgmOlFkteE5IeMFSlAaMJ74afsnET/ArdaoGob1A hJnycynOJCKQOi/9IPSKkyDZcEiKZoFJc+ptMRgmbnMP0jSCpBfibDR+P25AnBy2nD0M +SdNbDjrDrSdP1YbFce+0KrLzRkFxB2B8U6YxurlFk+Rb2GqrIseuqwSH1zWcqR5h5+m JM7QT2PgI1yXUaktaggy/bwtDjbsrs0xSvBF4kXJQhBy9FbgodKTwPHtuSO6Fi+3AnWv pybrZI02H9GWPWNiQW577nuMaeDwupZ86JqpytIJpfJ8HQ4ODA64LSFGU11Oq0trObVr zXvQ== X-Gm-Message-State: AOJu0YwuIg5SpLd2mqOKlhUMCaHSx336ReeeiaSS9sLde7eymqtih6nO SB9YwHnydFrxQC9uwsEtgyc6plYrxBG1R0ne/dtVijt+gBsBkQYVReEJYO86aIEY X-Gm-Gg: AR+sD10tL5CIDaPK6A0b5KlXAtVTFUFQpv4YQr5LGVAXUJWbjyVRMbU5Cpylu1TFnii O03XhtssC0QpLIrE8vdf/a/8lvFdX0W4f8k02ha96AFpjK/bzxIBx77PrOeJWIZPS+3SEZ17ode Aufx7+A3E8w77ZGi4xfq85DvfOFR0pRdf+Nm2aZpb6xRh0WwVPlGTrqUsFQmPTPmer21kSVNzy/ oBDbahD1TzarBTDsR5K/iiH6WPEvDfcxg4gEgJeVXxRUSWVr8NYEGccn/z6ShCez4ZTOk1ta1wC L5/oQJrwklUir5dR3Y1TIFcwgmPkKjXzt3FnRT4YR39tVIWQchPmxgtHIBIM3nkKxFb0hjBsTnO tTXcvIjnUcPCyRFev5ZJxL7mIPUwNNk5buumdzqV67y5Ltc5VCuIbL/UodFaDHcMck/3VoknDq8 xK6DYUmg8yLPJcoVs1aOgBHdSt2BCJc05+Nz3bH4dbNd9YfdmcyWsXNVyFvBJsJL5SwsE8tQlKU g1XCPodAs2SgpnMS+VN5MS4XU1t9Fyu7Q== X-Received: by 2002:a17:902:ecd2:b0:2c2:cf20:213 with SMTP id d9443c01a7336-2d0523be26bmr118407965ad.29.1785821372144; Mon, 03 Aug 2026 22:29:32 -0700 (PDT) Received: from anna.. ([114.70.9.168]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04ae5a904sm47056345ad.20.2026.08.03.22.29.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 22:29:31 -0700 (PDT) From: chanyoung To: netdev@vger.kernel.org Cc: Sabrina Dubroca , Jakub Kicinski , John Fastabend , David Howells , Shuah Khan , linux-kselftest@vger.kernel.org, chanyoung , stable@vger.kernel.org Subject: [PATCH net v2 1/2] tls: don't leave a full plaintext sk_msg ring unpushed Date: Tue, 4 Aug 2026 14:28:35 +0900 Message-ID: <20260804052837.49015-2-ppoo1220@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260804052837.49015-1-ppoo1220@gmail.com> References: <20260804052837.49015-1-ppoo1220@gmail.com> Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When the copy path in tls_sw_sendmsg_locked() adds the fragment that fills the plaintext sk_msg ring, it does not set full_record, so the record is left full and unpushed. A later splice() then adds to an already full ring: sk_msg_page_add() has no fullness check of its own, so sg.end wraps onto sg.start and the ring appears empty. Fragments added after that overwrite live entries, and sg.size no longer matches what is reachable between sg.start and sg.end, so pushing the record runs the scatterwalk off the end of the scatterlist. An unprivileged user can trigger this on a loopback TCP socket with the "tls" ULP attached: BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:memcpy_from_scatterwalk+0x32/0xc0 Call Trace: skcipher_walk_next+0x1d1/0x2c0 gcm_encrypt_aesni_avx+0x1e9/0x220 bpf_exec_tx_verdict+0x3bb/0x860 tls_sw_sendmsg+0xa1a/0xca0 __sys_sendto+0x1da/0x1f0 Set full_record in the copy path when the ring becomes full, and push a record that is already full on entry to the sendmsg loop. Suggested-by: Sabrina Dubroca Fixes: fe1e81d4f73b ("tls/sw: Support MSG_SPLICE_PAGES") Cc: stable@vger.kernel.org Signed-off-by: chanyoung --- net/tls/tls_sw.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c index d4afc90fd79..d2e399be8ef 100644 --- a/net/tls/tls_sw.c +++ b/net/tls/tls_sw.c @@ -832,6 +832,14 @@ static int tls_sw_sendmsg_locked(struct sock *sk, struct msghdr *msg, if (!sk_stream_memory_free(sk)) goto wait_for_sndbuf; + /* open record may be full if we couldn't push it in the last sendmsg call */ + if (sk_msg_full(msg_pl)) { + full_record = true; + sk_msg_trim(sk, msg_en, + msg_pl->sg.size + prot->overhead_size); + goto copied; + } + alloc_encrypted: ret = tls_alloc_encrypted_msg(sk, required_size); if (ret) { @@ -921,6 +929,12 @@ static int tls_sw_sendmsg_locked(struct sock *sk, struct msghdr *msg, msg_pl, try_to_copy); if (ret < 0) goto trim_sgl; + + if (sk_msg_full(msg_pl)) { + full_record = true; + sk_msg_trim(sk, msg_en, + msg_pl->sg.size + prot->overhead_size); + } } /* Open records defined only if successfully copied, otherwise -- 2.43.0