Re: [BUG] net/bridge: out-of-bounds in br_forward()

Florian Westphal <[email protected]>
Newsgroups gmane.linux.network.bridge
Message-ID <apBJyKJ7zs4kUmpd__22313.6970003665$1787841238$gmane$org@strlen.de>
co <[email protected]> wrote:
> We found a bug reachable in:
> 
>     path    net/bridge/netfilter
>     crash   out-of-bounds in br_forward()
>     commit  7b5344954050 ("Merge tag 'nf-26-08-10' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf")

I'm looking into these reports, I think this is the same
underlying bug as the other report; a variant of

ccb9fd4b8753 ("netfilter: revalidate bridge ports")

That bug uses nfnetlink_queue for RCU escape, the other two reports
use defrag engine.

And sure, its br_netfilter again -- I think we will have to consider
removing it even though it will break existing setups.

As a compromise, I suggest to reject br_netfilter in user namespaces,
i.e. call_iptables cannot be enabled anymore unless you have
CAP_NET_ADMIN in init net.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.