Netdev List
 help / color / mirror / Atom feed
From: Ido Schimmel <idosch@nvidia.com>
To: netdev@vger.kernel.org
Cc: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
	edumazet@google.com, dsahern@kernel.org, horms@kernel.org,
	willemdebruijn.kernel@gmail.com, aksecurity@gmail.com,
	noam.caspi@mail.huji.ac.il, Ido Schimmel <idosch@nvidia.com>,
	stable@vger.kernel.org
Subject: [PATCH net 2/4] ipv4: udp: Create exceptions when socket matching failed
Date: Wed, 26 Aug 2026 17:37:33 +0300	[thread overview]
Message-ID: <20260826143735.1819315-3-idosch@nvidia.com> (raw)
In-Reply-To: <20260826143735.1819315-1-idosch@nvidia.com>

Currently, when ICMP Fragmentation Needed and Redirect Message packets
are locally delivered and quote a UDP packet, a FIB nexthop exception
(FNHE) is created only if the kernel can match the UDP packet to an
existing socket.

This behavior allows off-path attackers to conduct a side-channel attack
on the FNHE cache in order to discover the ephemeral port used by a
connected UDP socket.

Commit 6457378fe796 ("ipv4: use siphash instead of Jenkins in
fnhe_hashfun()") and commit 67d6d681e15b ("ipv4: make exception cache
less predictible") tried to mitigate such attacks by making it harder
for attackers to discover hash collisions in the FNHE cache and by
randomizing the number of exceptions a hash bucket can hold,
respectively. Unfortunately, both of the mitigations can be bypassed.

Instead, mitigate such attacks by always creating a FNHE, even if socket
matching failed. Do that by calling ipv4_update_pmtu() and
ipv4_redirect(), the helpers used when the quoted packet did not
originate from a socket. The resulting FNHE is indistinguishable from
the one created when socket matching succeeded, both in terms of cache
occupancy and in terms of its contents.

Pass an oif of 0, in a similar fashion to icmp_err().

Note that this does not allow attackers to create FNHEs that they could
not create before, as both helpers can already be reached with little to
no validation. For example, by sending an ICMP error that quotes an ICMP
Echo Reply or one that quotes a UDP source port that matches a wildcard
socket.

Also create a FNHE when a socket does not wish to accept PMTU updates
(e.g., by setting 'IP_PMTUDISC_OMIT'). Otherwise, the fact that a FNHE
was not created can indicate to an off-path attacker that a socket
exists. This applies to all ipv4_sk_update_pmtu() callers, so ping and
raw sockets that decline PMTU updates will now create a FNHE as well.
Such sockets are not affected by it, as ip_skb_dst_mtu() uses the MTU of
the device for them.

Fixes: 4895c771c7f0 ("ipv4: Add FIB nexthop exceptions.")
Cc: stable@vger.kernel.org
Reported-by: Amit Klein <aksecurity@gmail.com>
Reported-by: Noam Caspi <noam.caspi@mail.huji.ac.il>
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
---
 net/ipv4/route.c |  8 +++++---
 net/ipv4/udp.c   | 10 ++++++++++
 2 files changed, 15 insertions(+), 3 deletions(-)

diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 37674d76f90f..692298078700 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -1157,10 +1157,12 @@ void ipv4_sk_update_pmtu(struct sk_buff *skb, struct sock *sk, u32 mtu)
 	bool new = false;
 	struct net *net = sock_net(sk);
 
-	bh_lock_sock(sk);
+	if (!ip_sk_accept_pmtu(sk)) {
+		ipv4_update_pmtu(skb, net, mtu, 0, sk->sk_protocol);
+		return;
+	}
 
-	if (!ip_sk_accept_pmtu(sk))
-		goto out;
+	bh_lock_sock(sk);
 
 	odst = sk_dst_get(sk);
 
diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index af9603217444..6981526bd59c 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -900,6 +900,15 @@ static struct sock *__udp4_lib_err_encap(struct net *net,
 	return sk;
 }
 
+static void udp_err_no_sk(struct net *net, struct sk_buff *skb, int type,
+			  int code, u32 info)
+{
+	if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED)
+		ipv4_update_pmtu(skb, net, info, 0, IPPROTO_UDP);
+	else if (type == ICMP_REDIRECT)
+		ipv4_redirect(skb, net, 0, IPPROTO_UDP);
+}
+
 /*
  * This routine is called by the ICMP module when it gets some
  * sort of error condition.  If err < 0 then the socket should
@@ -938,6 +947,7 @@ int udp_err(struct sk_buff *skb, u32 info)
 			sk = ERR_PTR(-ENOENT);
 
 		if (IS_ERR(sk)) {
+			udp_err_no_sk(net, skb, type, code, info);
 			__ICMP_INC_STATS(net, ICMP_MIB_INERRORS);
 			return PTR_ERR(sk);
 		}
-- 
2.55.0


  parent reply	other threads:[~2026-08-26 14:39 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26 14:37 [PATCH net 0/4] Mitigate a side channel in routing exception caches Ido Schimmel
2026-08-26 14:37 ` [PATCH net 1/4] ipv6: Fix redirect exception creation for UDP/RAW sockets Ido Schimmel
2026-08-26 14:37 ` Ido Schimmel [this message]
2026-08-26 15:50   ` [PATCH net 2/4] ipv4: udp: Create exceptions when socket matching failed Eric Dumazet
2026-08-27 19:33   ` Ido Schimmel
2026-08-26 14:37 ` [PATCH net 3/4] ipv6: " Ido Schimmel
2026-08-26 15:51   ` Eric Dumazet
2026-08-26 14:37 ` [PATCH net 4/4] selftests: net: Add exception cache tests Ido Schimmel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260826143735.1819315-3-idosch@nvidia.com \
    --to=idosch@nvidia.com \
    --cc=aksecurity@gmail.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=noam.caspi@mail.huji.ac.il \
    --cc=pabeni@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=willemdebruijn.kernel@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox