From: Nikolay Aleksandrov <razor@blackwall.org>
To: Zhao ShiRong <shxzhaosr@163.com>, netdev@vger.kernel.org
Cc: Ido Schimmel <idosch@nvidia.com>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
bridge@lists.linux.dev,
syzbot+128e9f5a0f85a51215b1@syzkaller.appspotmail.com
Subject: Re: [PATCH net] bridge: skip generic XDP on locally re-injected packets
Date: Mon, 31 Aug 2026 15:31:19 +0300 [thread overview]
Message-ID: <b30a2594-b154-4f52-9afd-2db0f9d78bb3@blackwall.org> (raw)
In-Reply-To: <20260831113051.13072-1-shxzhaosr@163.com>
On 31/08/2026 14:30, Zhao ShiRong wrote:
> Packets locally delivered by the bridge are re-injected into the
> receive path via br_pass_frame_up() -> br_netif_receive_skb() ->
> netif_receive_skb() with skb->dev set to the bridge device. If the
> bridge device has an XDP program attached, __netif_receive_skb_core()
> runs do_xdp_generic() a second time on such packets.
>
> A locally-delivered packet that was allocated on the TX path (e.g. an
> MLD packet built by mld_newpack()) does not carry the
> XDP_PACKET_HEADROOM that generic XDP requires, so
> netif_skb_check_for_xdp() calls pskb_expand_head() and reallocates the
> skb head buffer. This frees the head that the bridge rx path
> (br_handle_frame() / br_handle_frame_finish()) is still using, leading
> to a use-after-free read in br_handle_frame():
>
> BUG: KASAN: slab-use-after-free in is_multicast_ether_addr [inline]
> BUG: KASAN: slab-use-after-free in is_valid_ether_addr [inline]
> BUG: KASAN: slab-use-after-free in br_handle_frame+0xcfb/0x1510 net/bridge/br_input.c:349
>
> netif_receive_generic_xdp() already refuses to run generic XDP on
> reinjected packets by checking skb_is_redirected(). Reuse that marker:
> set it right before the bridge re-injects the packet, so generic XDP is
> skipped and the head buffer is left intact.
>
> Reported-by: syzbot+128e9f5a0f85a51215b1@syzkaller.appspotmail.com
> Link: https://lore.kernel.org/all/6a6d4406.2d659fcc.1d46f5.01ad.GAE@google.com/T/
> Signed-off-by: Zhao ShiRong <shxzhaosr@163.com>
> ---
> net/bridge/br_input.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/net/bridge/br_input.c b/net/bridge/br_input.c
> --- a/net/bridge/br_input.c
> +++ b/net/bridge/br_input.c
> @@ -26,6 +26,12 @@ static int
> br_netif_receive_skb(struct net *net, struct sock *sk, struct sk_buff *skb)
> {
> br_drop_fake_rtable(skb);
> +
> + /* Re-injected for local delivery: do not let generic XDP run on the
> + * bridge device a second time, it could reallocate the head via
> + * pskb_expand_head() and free a buffer still in use.
> + */
> + skb_set_redirected_noclear(skb, false);
> return netif_receive_skb(skb);
> }
>
> --
> 2.43.0
>
Nacked-by: Nikolay Aleksandrov <razor@blackwall.org>
This is wrong on multiple levels, use your head for 2 seconds before blindly
sending AI crap. This was sent ~2 hours after the report was sent, did you
even test your patch or just hit send? Very disturbing practice anyway.
Perhaps we should clone the skb for passing it up to the bridge when a fwding
helper is using it (i.e. when there are actually clones).
next prev parent reply other threads:[~2026-08-31 12:31 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 11:30 [PATCH net] bridge: skip generic XDP on locally re-injected packets Zhao ShiRong
2026-08-31 12:25 ` Ido Schimmel
2026-08-31 12:38 ` Nikolay Aleksandrov
2026-08-31 12:31 ` Nikolay Aleksandrov [this message]
[not found] ` <15142192.95bb.1a057e13984.Coremail.shxzhaosr@163.com>
2026-08-31 13:17 ` 回复:Re: " Nikolay Aleksandrov
2026-09-04 22:25 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b30a2594-b154-4f52-9afd-2db0f9d78bb3@blackwall.org \
--to=razor@blackwall.org \
--cc=bridge@lists.linux.dev \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=shxzhaosr@163.com \
--cc=syzbot+128e9f5a0f85a51215b1@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox