[PATCH net] gtp: fix NULL pointer dereference in gtp0_handle_echo_resp()

"Cen Zhang (Microsoft)" <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.kernel
Message-ID <[email protected]>
In gtp_create_sockets(), gtp->sk_created is set to true before gtp->sk0
and gtp->sk1u are assigned. A concurrent GTP Echo Response packet on
another CPU observes sk_created == true and dereferences the still-NULL
gtp->sk0 in gtp0_handle_echo_resp(), causing a kernel panic.

  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
  RIP: 0010:gtp_encap_recv  (drivers/net/gtp.c:542 gtp0_handle_echo_resp)
  Call Trace:
   <IRQ>
   udp_queue_rcv_one_skb
   ip_protocol_deliver_rcu
   ip_local_deliver
  Kernel panic - not syncing: Fatal exception in interrupt

Reorder the assignments so that gtp->sk0 and gtp->sk1u are fully visible
before gtp->sk_created is set to true. This ensures no concurrent packet
path can observe the flag without valid socket pointers.

Fixes: b20dc3c68458 ("gtp: Allow to create GTP device without FDs")
Reported-by: [email protected]
Reported-by: Xiang Mei (Microsoft) <[email protected]>
Reported-by: Cen Zhang (Microsoft) <[email protected]>
Signed-off-by: Cen Zhang (Microsoft) <[email protected]>
---
 drivers/net/gtp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/gtp.c b/drivers/net/gtp.c
index 9a12cc53da00..2b5a8f6d24d0 100644
--- a/drivers/net/gtp.c
+++ b/drivers/net/gtp.c
@@ -1456,9 +1456,9 @@ static int gtp_create_sockets(struct gtp_dev *gtp, const struct nlattr *nla,
 		return PTR_ERR(sk1u);
 	}
 
-	gtp->sk_created = true;
 	gtp->sk0 = sk0;
 	gtp->sk1u = sk1u;
+	gtp->sk_created = true;
 
 	return 0;
 }
-- 
2.52.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.