Re: [PATCH net 1/2] net/iucv: drop HiperSockets frames from other network namespaces

Alexandra Winter <[email protected]>
Newsgroups org.kernel.vger.linux-s390,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>

On 15.08.26 18:07, Bryam Vargas via B4 Relay wrote:
> From: Bryam Vargas <[email protected]>
> 
> iucv_packet_type sets neither .dev nor .af_packet_net, so it lands in the
> machine-global ptype_base[] that __netif_receive_skb_core walks for every
> frame in every namespace, and afiucv_hs_rcv() ignores its dev argument.
> An ETH_P_AF_IUCV frame sent from any namespace holding CAP_NET_RAW is
> therefore matched against the global iucv_sk_list and can move a socket
> owned by the initial namespace: afiucv_hs_callback_synfin() and _fin()
> overwrite its sk_state, and _syn() builds an accept-queue child.
> 
> Filter on the namespace. The core does not do it for ptype_base[] --
> net/core/dev.c leaves namespace filtering to the ptype owner -- and
> net/x25/x25_dev.c and net/ieee802154/socket.c both test dev_net(dev) at
> exactly this point.
> 
> Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
> ---
>  net/iucv/af_iucv.c | 5 +++++
>  1 file changed, 5 insertions(+)
> 
> diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
> index ea047bab65e7..e3ec965d96ca 100644
> --- a/net/iucv/af_iucv.c
> +++ b/net/iucv/af_iucv.c
> @@ -2064,6 +2064,11 @@ static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
>  	int err = NET_RX_SUCCESS;
>  	char nullstring[8];
>  
> +	if (!net_eq(dev_net(dev), &init_net)) {
> +		kfree_skb(skb);
> +		return NET_RX_SUCCESS;
> +	}
> +
>  	if (!pskb_may_pull(skb, sizeof(*trans_hdr))) {
>  		kfree_skb(skb);
>  		return NET_RX_SUCCESS;
> 

I am wondering whether a check of
+		if (iucv_sk(sk)->hs_dev != dev)
+			continue;

would cover a broader range of issues.
I'll try to send a proper patch proposal.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.