* [PATCH net] vxlan: fix NULL deref when joining a group without a socket
@ 2026-09-29 12:22 Wentao Luo
2026-09-29 15:27 ` Fernando Fernandez Mancera
0 siblings, 1 reply; 4+ messages in thread
From: Wentao Luo @ 2026-09-29 12:22 UTC (permalink / raw)
To: netdev
Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Kuniyuki Iwashima, Edward Cree,
Fernando Fernandez Mancera, Antonio Quartulli, Jiri Benc
vxlan_sock_add() ignores -EAFNOSUPPORT when creating the IPv6 socket
of a metadata device, so the device can come up with vn6_sock NULL
after ipv6.disable=1. A later IPv6 multicast join still uses that
socket. vxlan_igmp_join() dereferences it and oopses.
This was observed on an external vnifilter device by adding an IPv6
group while the device was up:
BUG: KASAN: null-ptr-deref in vxlan_igmp_join+0xb8/0x18c
Read of size 8 at addr 0000000000000010 by task bridge/729
Call trace:
show_stack+0x18/0x24 (C)
dump_stack_lvl+0x78/0x90
print_report+0x468/0x5cc
kasan_report+0xa4/0xf0
__asan_load8+0x7c/0xd0
vxlan_igmp_join+0xb8/0x18c
vxlan_vni_update_group+0x2b4/0x390
vxlan_process_vni_filter+0xfe0/0x1750
vxlan_vnifilter_process+0x218/0x270
rtnetlink_rcv_msg+0x1ec/0x514
netlink_rcv_skb+0xc0/0x1f0
rtnetlink_rcv+0x18/0x24
netlink_unicast+0x4b8/0x558
netlink_sendmsg+0x2b8/0x584
...
Return -EAFNOSUPPORT from vxlan_igmp_join() and vxlan_igmp_leave()
when the address family has no socket. The same leave path runs while
rolling back a failed join.
Fixes: d074bf960044 ("vxlan: correctly handle ipv6.disable module
parameter")
Signed-off-by: Wentao Luo <luowentao077@gmail.com>
---
Simplest reproducer. Build with CONFIG_IPV6=y and boot with
ipv6.disable=1:
ip link add vxlan0 type vxlan external group ff05::1 dev lo dstport 4789
ip link set vxlan0 up
The NULL pointer dereference is then reproduced.
drivers/net/vxlan/vxlan_multicast.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/net/vxlan/vxlan_multicast.c
b/drivers/net/vxlan/vxlan_multicast.c
index 3b75b48dc726d..33ec1fd59ca82 100644
--- a/drivers/net/vxlan/vxlan_multicast.c
+++ b/drivers/net/vxlan/vxlan_multicast.c
@@ -29,6 +29,9 @@ int vxlan_igmp_join(struct vxlan_dev *vxlan, union
vxlan_addr *rip,
.imr_ifindex = ifindex,
};
+ if (!sock4)
+ return -EAFNOSUPPORT;
+
sk = sock4->sk;
lock_sock(sk);
ret = ip_mc_join_group(sk, &mreq);
@@ -37,6 +40,9 @@ int vxlan_igmp_join(struct vxlan_dev *vxlan, union
vxlan_addr *rip,
} else {
struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
+ if (!sock6)
+ return -EAFNOSUPPORT;
+
sk = sock6->sk;
lock_sock(sk);
ret = ipv6_sock_mc_join(sk, ifindex, &ip->sin6.sin6_addr);
@@ -62,6 +68,9 @@ int vxlan_igmp_leave(struct vxlan_dev *vxlan, union
vxlan_addr *rip,
.imr_ifindex = ifindex,
};
+ if (!sock4)
+ return -EAFNOSUPPORT;
+
sk = sock4->sk;
lock_sock(sk);
ret = ip_mc_leave_group(sk, &mreq);
@@ -70,6 +79,9 @@ int vxlan_igmp_leave(struct vxlan_dev *vxlan, union
vxlan_addr *rip,
} else {
struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
+ if (!sock6)
+ return -EAFNOSUPPORT;
+
sk = sock6->sk;
lock_sock(sk);
ret = ipv6_sock_mc_drop(sk, ifindex, &ip->sin6.sin6_addr);
--
2.43.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH net] vxlan: fix NULL deref when joining a group without a socket
2026-09-29 12:22 [PATCH net] vxlan: fix NULL deref when joining a group without a socket Wentao Luo
@ 2026-09-29 15:27 ` Fernando Fernandez Mancera
2026-09-30 6:03 ` Jiri Benc
0 siblings, 1 reply; 4+ messages in thread
From: Fernando Fernandez Mancera @ 2026-09-29 15:27 UTC (permalink / raw)
To: Wentao Luo, netdev
Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Kuniyuki Iwashima, Edward Cree, Antonio Quartulli,
Jiri Benc
On 9/29/26 2:22 PM, Wentao Luo wrote:
> vxlan_sock_add() ignores -EAFNOSUPPORT when creating the IPv6 socket
> of a metadata device, so the device can come up with vn6_sock NULL
> after ipv6.disable=1. A later IPv6 multicast join still uses that
> socket. vxlan_igmp_join() dereferences it and oopses.
>
> This was observed on an external vnifilter device by adding an IPv6
> group while the device was up:
>
> BUG: KASAN: null-ptr-deref in vxlan_igmp_join+0xb8/0x18c
> Read of size 8 at addr 0000000000000010 by task bridge/729
> Call trace:
> show_stack+0x18/0x24 (C)
> dump_stack_lvl+0x78/0x90
> print_report+0x468/0x5cc
> kasan_report+0xa4/0xf0
> __asan_load8+0x7c/0xd0
> vxlan_igmp_join+0xb8/0x18c
> vxlan_vni_update_group+0x2b4/0x390
> vxlan_process_vni_filter+0xfe0/0x1750
> vxlan_vnifilter_process+0x218/0x270
> rtnetlink_rcv_msg+0x1ec/0x514
> netlink_rcv_skb+0xc0/0x1f0
> rtnetlink_rcv+0x18/0x24
> netlink_unicast+0x4b8/0x558
> netlink_sendmsg+0x2b8/0x584
> ...
>
> Return -EAFNOSUPPORT from vxlan_igmp_join() and vxlan_igmp_leave()
> when the address family has no socket. The same leave path runs while
> rolling back a failed join.
>
> Fixes: d074bf960044 ("vxlan: correctly handle ipv6.disable module
> parameter")
> Signed-off-by: Wentao Luo <luowentao077@gmail.com>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Just a nit: the checks on the leave path are not necessary. While I
think it is fine to leave them just for the symmetry, I do not think we
can reach such path without succeeding during the join and if the join
succeeds it means ipv6 is not disabled.
> ---
> Simplest reproducer. Build with CONFIG_IPV6=y and boot with
> ipv6.disable=1:
>
> ip link add vxlan0 type vxlan external group ff05::1 dev lo dstport 4789
> ip link set vxlan0 up
>
> The NULL pointer dereference is then reproduced.
>
> drivers/net/vxlan/vxlan_multicast.c | 12 ++++++++++++
> 1 file changed, 12 insertions(+)
>
> diff --git a/drivers/net/vxlan/vxlan_multicast.c b/drivers/net/vxlan/
> vxlan_multicast.c
> index 3b75b48dc726d..33ec1fd59ca82 100644
> --- a/drivers/net/vxlan/vxlan_multicast.c
> +++ b/drivers/net/vxlan/vxlan_multicast.c
> @@ -29,6 +29,9 @@ int vxlan_igmp_join(struct vxlan_dev *vxlan, union
> vxlan_addr *rip,
> .imr_ifindex = ifindex,
> };
>
> + if (!sock4)
> + return -EAFNOSUPPORT;
> +
> sk = sock4->sk;
> lock_sock(sk);
> ret = ip_mc_join_group(sk, &mreq);
> @@ -37,6 +40,9 @@ int vxlan_igmp_join(struct vxlan_dev *vxlan, union
> vxlan_addr *rip,
> } else {
> struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
>
> + if (!sock6)
> + return -EAFNOSUPPORT;
> +
> sk = sock6->sk;
> lock_sock(sk);
> ret = ipv6_sock_mc_join(sk, ifindex, &ip->sin6.sin6_addr);
> @@ -62,6 +68,9 @@ int vxlan_igmp_leave(struct vxlan_dev *vxlan, union
> vxlan_addr *rip,
> .imr_ifindex = ifindex,
> };
>
> + if (!sock4)
> + return -EAFNOSUPPORT;
> +
> sk = sock4->sk;
> lock_sock(sk);
> ret = ip_mc_leave_group(sk, &mreq);
> @@ -70,6 +79,9 @@ int vxlan_igmp_leave(struct vxlan_dev *vxlan, union
> vxlan_addr *rip,
> } else {
> struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
>
> + if (!sock6)
> + return -EAFNOSUPPORT;
> +
> sk = sock6->sk;
> lock_sock(sk);
> ret = ipv6_sock_mc_drop(sk, ifindex, &ip->sin6.sin6_addr);
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] vxlan: fix NULL deref when joining a group without a socket
2026-09-29 15:27 ` Fernando Fernandez Mancera
@ 2026-09-30 6:03 ` Jiri Benc
2026-09-30 10:07 ` Fernando Fernandez Mancera
0 siblings, 1 reply; 4+ messages in thread
From: Jiri Benc @ 2026-09-30 6:03 UTC (permalink / raw)
To: Fernando Fernandez Mancera
Cc: Wentao Luo, netdev, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Kuniyuki Iwashima, Edward Cree,
Antonio Quartulli
On Tue, 29 Sep 2026 17:27:01 +0200, Fernando Fernandez Mancera wrote:
> On 9/29/26 2:22 PM, Wentao Luo wrote:
> > vxlan_sock_add() ignores -EAFNOSUPPORT when creating the IPv6 socket
> > of a metadata device, so the device can come up with vn6_sock NULL
> > after ipv6.disable=1. A later IPv6 multicast join still uses that
> > socket. vxlan_igmp_join() dereferences it and oopses.
> >
> > This was observed on an external vnifilter device by adding an IPv6
> > group while the device was up:
> >
> > BUG: KASAN: null-ptr-deref in vxlan_igmp_join+0xb8/0x18c
> > Read of size 8 at addr 0000000000000010 by task bridge/729
> > Call trace:
> > show_stack+0x18/0x24 (C)
> > dump_stack_lvl+0x78/0x90
> > print_report+0x468/0x5cc
> > kasan_report+0xa4/0xf0
> > __asan_load8+0x7c/0xd0
> > vxlan_igmp_join+0xb8/0x18c
> > vxlan_vni_update_group+0x2b4/0x390
> > vxlan_process_vni_filter+0xfe0/0x1750
> > vxlan_vnifilter_process+0x218/0x270
> > rtnetlink_rcv_msg+0x1ec/0x514
> > netlink_rcv_skb+0xc0/0x1f0
> > rtnetlink_rcv+0x18/0x24
> > netlink_unicast+0x4b8/0x558
> > netlink_sendmsg+0x2b8/0x584
> > ...
> >
> > Return -EAFNOSUPPORT from vxlan_igmp_join() and vxlan_igmp_leave()
> > when the address family has no socket. The same leave path runs while
> > rolling back a failed join.
> >
> > Fixes: d074bf960044 ("vxlan: correctly handle ipv6.disable module
> > parameter")
While I've introduced my share of bugs over the years, this one is not
introduced by my commit. Commit d074bf960044 specifically checks for
the metadata mode and leaves the ipv6 socket as NULL only in the
metadata mode. In the metadata mode, there's no multicast and the
vxlan_igmp_* functions are never reached. This was introduced by a
different commit.
With the current commit message:
Nacked-by: Jiri Benc <jbenc@redhat.com>
Please find the real cause, fix the Fixes header and resubmit.
Thanks,
Jiri
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] vxlan: fix NULL deref when joining a group without a socket
2026-09-30 6:03 ` Jiri Benc
@ 2026-09-30 10:07 ` Fernando Fernandez Mancera
0 siblings, 0 replies; 4+ messages in thread
From: Fernando Fernandez Mancera @ 2026-09-30 10:07 UTC (permalink / raw)
To: Jiri Benc
Cc: Wentao Luo, netdev, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Kuniyuki Iwashima, Edward Cree,
Antonio Quartulli
On 9/30/26 8:03 AM, Jiri Benc wrote:
> On Tue, 29 Sep 2026 17:27:01 +0200, Fernando Fernandez Mancera wrote:
>> On 9/29/26 2:22 PM, Wentao Luo wrote:
>>> vxlan_sock_add() ignores -EAFNOSUPPORT when creating the IPv6 socket
>>> of a metadata device, so the device can come up with vn6_sock NULL
>>> after ipv6.disable=1. A later IPv6 multicast join still uses that
>>> socket. vxlan_igmp_join() dereferences it and oopses.
>>>
>>> This was observed on an external vnifilter device by adding an IPv6
>>> group while the device was up:
>>>
>>> BUG: KASAN: null-ptr-deref in vxlan_igmp_join+0xb8/0x18c
>>> Read of size 8 at addr 0000000000000010 by task bridge/729
>>> Call trace:
>>> show_stack+0x18/0x24 (C)
>>> dump_stack_lvl+0x78/0x90
>>> print_report+0x468/0x5cc
>>> kasan_report+0xa4/0xf0
>>> __asan_load8+0x7c/0xd0
>>> vxlan_igmp_join+0xb8/0x18c
>>> vxlan_vni_update_group+0x2b4/0x390
>>> vxlan_process_vni_filter+0xfe0/0x1750
>>> vxlan_vnifilter_process+0x218/0x270
>>> rtnetlink_rcv_msg+0x1ec/0x514
>>> netlink_rcv_skb+0xc0/0x1f0
>>> rtnetlink_rcv+0x18/0x24
>>> netlink_unicast+0x4b8/0x558
>>> netlink_sendmsg+0x2b8/0x584
>>> ...
>>>
>>> Return -EAFNOSUPPORT from vxlan_igmp_join() and vxlan_igmp_leave()
>>> when the address family has no socket. The same leave path runs while
>>> rolling back a failed join.
>>>
>>> Fixes: d074bf960044 ("vxlan: correctly handle ipv6.disable module
>>> parameter")
>
> While I've introduced my share of bugs over the years, this one is not
> introduced by my commit. Commit d074bf960044 specifically checks for
> the metadata mode and leaves the ipv6 socket as NULL only in the
> metadata mode. In the metadata mode, there's no multicast and the
> vxlan_igmp_* functions are never reached. This was introduced by a
> different commit.
>
> With the current commit message:
>
> Nacked-by: Jiri Benc <jbenc@redhat.com>
>
> Please find the real cause, fix the Fixes header and resubmit.
>
That is fair, thanks Jiri. I didn't realize when commit d074bf960044 was
written, metadata mode did not support multicast. It seems the real
Fixes header should be:
Fixes: f9c4bb0b245c ("vxlan: vni filtering support on collect metadata
device")
This commit introduced the multicast support for metadata mode and
missed the NULL check.
> Thanks,
>
> Jiri
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-30 10:09 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29 12:22 [PATCH net] vxlan: fix NULL deref when joining a group without a socket Wentao Luo
2026-09-29 15:27 ` Fernando Fernandez Mancera
2026-09-30 6:03 ` Jiri Benc
2026-09-30 10:07 ` Fernando Fernandez Mancera
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox