Re: [PATCH ipsec v2] xfrm: fix compat ALLOCSPI request use-after-free

Steffen Klassert <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On Tue, Aug 04, 2026 at 06:10:37AM +0000, David Lee wrote:
> From: Kyle Zeng <[email protected]>
> 
> xfrm_state_netlink() builds the ALLOCSPI response with
> dump_one_state(), which already calls alloc_compat() with the response
> skb and header.
> 
> xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
> original request skb and its header. For a compat request, the
> translator therefore interprets the 228-byte compat xfrm_userspi_info
> as the 232-byte native layout and reads four bytes past the declared
> payload. It also publishes the translated child through the request's
> frag_list.
> 
> A multicast clone of the request shares skb_shared_info and can observe
> that child. xfrm_user_rcv_msg() frees it after the request handler
> returns, racing a compat receiver which may still be copying from it and
> resulting in a use-after-free.
> 
> Remove the redundant conversion. The response keeps its correct compat
> translation from dump_one_state(), and no child is attached to the
> inbound request.
> 
> Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
> Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber
> Signed-off-by: Kyle Zeng <[email protected]>
> Co-developed-by: David Lee <[email protected]>
> Signed-off-by: David Lee <[email protected]>

Applied, thanks a lot!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.