From: Jiri Benc <jbenc@redhat.com>
To: Fernando Fernandez Mancera <fmancera@suse.de>
Cc: Wentao Luo <luowentao077@gmail.com>,
netdev@vger.kernel.org, Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Edward Cree <ecree.xilinx@gmail.com>,
Antonio Quartulli <antonio@openvpn.net>
Subject: Re: [PATCH net] vxlan: fix NULL deref when joining a group without a socket
Date: Wed, 30 Sep 2026 08:03:53 +0200 [thread overview]
Message-ID: <20260930080353.0ccae75b@griffin> (raw)
In-Reply-To: <b3682f3b-f895-4843-815f-7f8a09530ba3@suse.de>
On Tue, 29 Sep 2026 17:27:01 +0200, Fernando Fernandez Mancera wrote:
> On 9/29/26 2:22 PM, Wentao Luo wrote:
> > vxlan_sock_add() ignores -EAFNOSUPPORT when creating the IPv6 socket
> > of a metadata device, so the device can come up with vn6_sock NULL
> > after ipv6.disable=1. A later IPv6 multicast join still uses that
> > socket. vxlan_igmp_join() dereferences it and oopses.
> >
> > This was observed on an external vnifilter device by adding an IPv6
> > group while the device was up:
> >
> > BUG: KASAN: null-ptr-deref in vxlan_igmp_join+0xb8/0x18c
> > Read of size 8 at addr 0000000000000010 by task bridge/729
> > Call trace:
> > show_stack+0x18/0x24 (C)
> > dump_stack_lvl+0x78/0x90
> > print_report+0x468/0x5cc
> > kasan_report+0xa4/0xf0
> > __asan_load8+0x7c/0xd0
> > vxlan_igmp_join+0xb8/0x18c
> > vxlan_vni_update_group+0x2b4/0x390
> > vxlan_process_vni_filter+0xfe0/0x1750
> > vxlan_vnifilter_process+0x218/0x270
> > rtnetlink_rcv_msg+0x1ec/0x514
> > netlink_rcv_skb+0xc0/0x1f0
> > rtnetlink_rcv+0x18/0x24
> > netlink_unicast+0x4b8/0x558
> > netlink_sendmsg+0x2b8/0x584
> > ...
> >
> > Return -EAFNOSUPPORT from vxlan_igmp_join() and vxlan_igmp_leave()
> > when the address family has no socket. The same leave path runs while
> > rolling back a failed join.
> >
> > Fixes: d074bf960044 ("vxlan: correctly handle ipv6.disable module
> > parameter")
While I've introduced my share of bugs over the years, this one is not
introduced by my commit. Commit d074bf960044 specifically checks for
the metadata mode and leaves the ipv6 socket as NULL only in the
metadata mode. In the metadata mode, there's no multicast and the
vxlan_igmp_* functions are never reached. This was introduced by a
different commit.
With the current commit message:
Nacked-by: Jiri Benc <jbenc@redhat.com>
Please find the real cause, fix the Fixes header and resubmit.
Thanks,
Jiri
next prev parent reply other threads:[~2026-09-30 6:04 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 12:22 [PATCH net] vxlan: fix NULL deref when joining a group without a socket Wentao Luo
2026-09-29 15:27 ` Fernando Fernandez Mancera
2026-09-30 6:03 ` Jiri Benc [this message]
2026-09-30 10:07 ` Fernando Fernandez Mancera
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930080353.0ccae75b@griffin \
--to=jbenc@redhat.com \
--cc=andrew+netdev@lunn.ch \
--cc=antonio@openvpn.net \
--cc=davem@davemloft.net \
--cc=ecree.xilinx@gmail.com \
--cc=edumazet@kernel.org \
--cc=fmancera@suse.de \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=luowentao077@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox