[PATCH nf] netfilter: nfnetlink_log: cope with concurrent instance destruction
Florian Westphal <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <[email protected]> |
Instances are refcounted. However, only memory release happens on the
1 -> 0 transition; the unlink from hashes can occur with any refcount.
Uncooperative userspace can force a situation where a queue is pending
for destruction from netlink event while a different socket with same
portid processes an UNBIND request.
With right timing, this will unhash the instance again:
Oops: general protection fault, [..]
Call Trace:
<TASK>
nfulnl_recv_config+0x31a/0xd50
nfnetlink_rcv_msg+0x7c2/0xeb0
Fixes: 0597f2680d66 ("[NETFILTER]: Add new "nfnetlink_log" userspace packet logging facility")
Reported-by: Eulgyu Kim <[email protected]>
Reported-by: Jaeyoung Chung <[email protected]>
Signed-off-by: Florian Westphal <[email protected]>
---
net/netfilter/nfnetlink_log.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nfnetlink_log.c b/net/netfilter/nfnetlink_log.c
index 6c7fa2ed34f5..8fc002ae08bc 100644
--- a/net/netfilter/nfnetlink_log.c
+++ b/net/netfilter/nfnetlink_log.c
@@ -228,13 +228,18 @@ static void __nfulnl_flush(struct nfulnl_instance *inst);
static void
__instance_destroy(struct nfulnl_instance *inst)
{
+ spin_lock(&inst->lock);
+ if (inst->copy_mode == NFULNL_COPY_DISABLED) {
+ /* attempt to UNBIND a queue already pending
+ * destruction via netlink close event. Ignore.
+ */
+ spin_unlock(&inst->lock);
+ return;
+ }
+
/* first pull it out of the global list */
hlist_del_rcu(&inst->hlist);
- /* then flush all pending packets from skb */
-
- spin_lock(&inst->lock);
-
/* lockless readers wont be able to use us */
inst->copy_mode = NFULNL_COPY_DISABLED;
--
2.54.0