[PATCH net v2 0/8] net: fixes for requests completing on a socket that no longer listens

Hyunwoo Kim <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
connect(AF_UNSPEC) and listen() move a socket back and forth between
listener and active session. IPV6_ADDRFORM on top of that turns an
AF_INET6 socket into an AF_INET one.

Two things follow. One is that what the socket had before the change is
left behind: requests still in the ehash, and parent fields a child
inherits. The other is that the socket is used while it is changing.
tcp_check_req() does not hold the listener lock, and tcp_v{4,6}_rcv()
reads sk_state twice without it on the listener path.

Patch 2 is neither. After a reuseport migration the listener that counted
a request and the listener the count is decremented on are not the same.
It goes with patch 3 because patch 3 needs it. Nothing ever resets that
count, so patch 3 on its own has a check that can be bypassed.

Patches 2, 6, 7 and 8 are new in v2.

Hyunwoo Kim (8):
  tcp: fix use-after-free of the listener's ipv6_pinfo after
    IPV6_ADDRFORM
  tcp: fix imbalanced icsk_accept_queue count in tcp_check_req()
  ipv6: fix request socket use-after-free after IPV6_ADDRFORM
  net: fix out-of-bounds write in sk_clone() racing with IPV6_ADDRFORM
  tcp: do not inherit out_of_order_queue from parent
  tcp: fix use-after-free in the lockless listener path
  net: clear sk_tsq_flags in sk_clone()
  tcp: do not inherit retransmit state from parent

 include/net/tcp.h        |  2 ++
 net/core/sock.c          |  3 +-
 net/ipv4/tcp_input.c     | 64 +++++++++++++++++++++++-----------------
 net/ipv4/tcp_ipv4.c      | 52 ++++++++++++++++++++++++++++++--
 net/ipv4/tcp_minisocks.c |  9 +++++-
 net/ipv6/af_inet6.c      |  4 +++
 net/ipv6/ipv6_sockglue.c | 15 ++++++++++
 net/ipv6/tcp_ipv6.c      | 44 +++++++++++++++++++++++++--
 8 files changed, 160 insertions(+), 33 deletions(-)

-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.