From mboxrd@z Thu Jan 1 00:00:00 1970 From: Sergei Shtylyov Subject: Re: [PATCH] ravb: Fix use-after-free on `ifconfig eth0 down` Date: Tue, 6 Jun 2017 12:35:30 +0300 Message-ID: References: <20170605220810.3933-1-erosca@de.adit-jv.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Cc: netdev@vger.kernel.org, linux-renesas-soc@vger.kernel.org To: Eugeniu Rosca , davem@davemloft.net, horms+renesas@verge.net.au, kazuya.mizuguchi.ks@renesas.com Return-path: Received: from mail-lf0-f49.google.com ([209.85.215.49]:35145 "EHLO mail-lf0-f49.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751383AbdFFJfd (ORCPT ); Tue, 6 Jun 2017 05:35:33 -0400 Received: by mail-lf0-f49.google.com with SMTP id p189so17525266lfe.2 for ; Tue, 06 Jun 2017 02:35:32 -0700 (PDT) In-Reply-To: <20170605220810.3933-1-erosca@de.adit-jv.com> Sender: netdev-owner@vger.kernel.org List-ID: Hello! On 6/6/2017 1:08 AM, Eugeniu Rosca wrote: > Commit a47b70ea86bd ("ravb: unmap descriptors when freeing rings") has > introduced the issue seen in [1] reproduced on H3ULCB board. > > Fix this by relocating the RX skb ringbuffer free operation, so that > swiotlb page unmapping can be done first. Freeing of aligned TX buffers > is not relevant to the issue seen in [1]. Still, reposition TX free > calls as well, to have all kfree() operations performed consistently > _after_ dma_unmap_*()/dma_free_*(). Perhaps it's a material of a separate cleanup patch? > [1] Console screenshot with the problem reproduced: > > salvator-x login: root > root@salvator-x:~# ifconfig eth0 up > Micrel KSZ9031 Gigabit PHY e6800000.ethernet-ffffffff:00: \ > attached PHY driver [Micrel KSZ9031 Gigabit PHY] \ > (mii_bus:phy_addr=e6800000.ethernet-ffffffff:00, irq=235) > IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready > root@salvator-x:~# > root@salvator-x:~# ifconfig eth0 down > ================================================================== > BUG: KASAN: use-after-free in swiotlb_tbl_unmap_single+0xc4/0x35c > Write of size 1538 at addr ffff8006d884f780 by task ifconfig/1649 > > CPU: 0 PID: 1649 Comm: ifconfig Not tainted 4.12.0-rc4-00004-g112eb07287d1 #32 > Hardware name: Renesas H3ULCB board based on r8a7795 (DT) > Call trace: > [] dump_backtrace+0x0/0x3a4 > [] show_stack+0x14/0x1c > [] dump_stack+0xf8/0x150 > [] print_address_description+0x7c/0x330 > [] kasan_report+0x2e0/0x2f4 > [] check_memory_region+0x20/0x14c > [] memcpy+0x48/0x68 > [] swiotlb_tbl_unmap_single+0xc4/0x35c > [] unmap_single+0x90/0xa4 > [] swiotlb_unmap_page+0xc/0x14 > [] __swiotlb_unmap_page+0xcc/0xe4 > [] ravb_ring_free+0x514/0x870 > [] ravb_close+0x288/0x36c > [] __dev_close_many+0x14c/0x174 > [] __dev_close+0xc8/0x144 > [] __dev_change_flags+0xd8/0x194 > [] dev_change_flags+0x60/0xb0 > [] devinet_ioctl+0x484/0x9d4 > [] inet_ioctl+0x190/0x194 > [] sock_do_ioctl+0x78/0xa8 > [] sock_ioctl+0x110/0x3c4 > [] vfs_ioctl+0x90/0xa0 > [] do_vfs_ioctl+0x148/0xc38 > [] SyS_ioctl+0x44/0x74 > [] el0_svc_naked+0x24/0x28 > > The buggy address belongs to the page: > page:ffff7e001b6213c0 count:0 mapcount:0 mapping: (null) index:0x0 > flags: 0x4000000000000000() > raw: 4000000000000000 0000000000000000 0000000000000000 00000000ffffffff > raw: 0000000000000000 ffff7e001b6213e0 0000000000000000 0000000000000000 > page dumped because: kasan: bad access detected > > Memory state around the buggy address: > ffff8006d884f680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff > ffff8006d884f700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff >> ffff8006d884f780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff > ^ > ffff8006d884f800: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff > ffff8006d884f880: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff > ================================================================== > Disabling lock debugging due to kernel taint > root@salvator-x:~# > > Fixes: a47b70ea86bd ("ravb: unmap descriptors when freeing rings") > Signed-off-by: Eugeniu Rosca [...] Acked-by: Sergei Shtylyov MBR, Sergei