[BUG] null-ptr-deref bug in sctp_packet_bundle_auth

Chen Zhen <[email protected]>
Newsgroups org.kernel.vger.linux-sctp
Message-ID <[email protected]>
Hi all,

We tested with syzkaller on linux-6.6 and it reported a null-ptr-deref bug:

==================================================================
general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
CPU: 0 PID: 16 Comm: ksoftirqd/0 Tainted: G W 6.6.0 #2
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:sctp_packet_bundle_auth net/sctp/output.c:264 [inline]
RIP: 0010:sctp_packet_append_chunk+0xb36/0x1260 net/sctp/output.c:401
Code: 4c 89 f2 48 c1 ea 03 80 3c 02 00 0f 85 93 05 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 7b 40 49 8d 7f 1c 48 89 fa 48 c1 ea 03 <0f> b6 14 02 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 57
RSP: 0018:ffffc9000010efe8 EFLAGS: 00010207
RAX: dffffc0000000000 RBX: ffff88810c746000 RCX: ffffffff8d758fca
RDX: 0000000000000003 RSI: ffff888100d1cd40 RDI: 000000000000001c
RBP: ffff88811dea8b78 R08: 0000000000000000 R09: fffffbfff27f8b7d
R10: fffffbfff27f8b7c R11: ffffffff93fc5be7 R12: ffff88804247c000
R13: ffff88811dea8bb8 R14: ffff88810c746040 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88816e600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 000000011dfb4002 CR4: 0000000000170ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600
Call Trace:

sctp_packet_transmit_chunk+0x31/0x250 net/sctp/output.c:189
sctp_outq_flush_data+0xa29/0x26d0 net/sctp/outqueue.c:1111
sctp_outq_flush+0xc80/0x1240 net/sctp/outqueue.c:1217
sctp_cmd_interpreter.isra.0+0x19a5/0x62c0 net/sctp/sm_sideeffect.c:1787
sctp_side_effects net/sctp/sm_sideeffect.c:1198 [inline]
sctp_do_sm+0x1a3/0x670 net/sctp/sm_sideeffect.c:1169
sctp_assoc_bh_rcv+0x33e/0x640 net/sctp/associola.c:1052
sctp_inq_push+0x1dd/0x280 net/sctp/inqueue.c:88
sctp_rcv+0x11ae/0x3100 net/sctp/input.c:243
sctp6_rcv+0x3d/0x60 net/sctp/ipv6.c:1127
ip6_protocol_deliver_rcu+0x12c1/0x1e40 net/ipv6/ip6_input.c:438
ip6_input_finish+0xc8/0x260 net/ipv6/ip6_input.c:483
NF_HOOK include/linux/netfilter.h:308 [inline]
ip6_input+0xd1/0x430 net/ipv6/ip6_input.c:492
dst_input include/net/dst.h:487 [inline]
ip6_rcv_finish+0x1b9/0x5c0 net/ipv6/ip6_input.c:79
NF_HOOK include/linux/netfilter.h:308 [inline]
ipv6_rcv+0xf8/0x440 net/ipv6/ip6_input.c:310
__netif_receive_skb_one_core+0x133/0x1f0 net/core/dev.c:5603
__netif_receive_skb+0x24/0x1c0 net/core/dev.c:5717
process_backlog+0x21d/0x7e0 net/core/dev.c:6045
__napi_poll+0xc2/0x690 net/core/dev.c:6607
napi_poll net/core/dev.c:6674 [inline]
net_rx_action+0x87d/0xce0 net/core/dev.c:6810
handle_softirqs+0x1b4/0x700 kernel/softirq.c:578
run_ksoftirqd kernel/softirq.c:997 [inline]
run_ksoftirqd+0x2f/0x60 kernel/softirq.c:989
smpboot_thread_fn+0x3b9/0x860 kernel/smpboot.c:164
kthread+0x324/0x420 kernel/kthread.c:388
ret_from_fork+0x49/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:293

Modules linked in:
kernel fault(0x1) notification starting on CPU 0
kernel fault(0x1) notification finished on CPU 0
---[ end trace 0000000000000000 ]---
RIP: 0010:sctp_packet_bundle_auth net/sctp/output.c:264 [inline]
RIP: 0010:sctp_packet_append_chunk+0xb36/0x1260 net/sctp/output.c:401
Code: 4c 89 f2 48 c1 ea 03 80 3c 02 00 0f 85 93 05 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 7b 40 49 8d 7f 1c 48 89 fa 48 c1 ea 03 <0f> b6 14 02 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 57
RSP: 0018:ffffc9000010efe8 EFLAGS: 00010207
RAX: dffffc0000000000 RBX: ffff88810c746000 RCX: ffffffff8d758fca
RDX: 0000000000000003 RSI: ffff888100d1cd40 RDI: 000000000000001c
RBP: ffff88811dea8b78 R08: 0000000000000000 R09: fffffbfff27f8b7d
R10: fffffbfff27f8b7c R11: ffffffff93fc5be7 R12: ffff88804247c000
R13: ffff88811dea8bb8 R14: ffff88810c746040 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88816e600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 000000011dfb4002 CR4: 0000000000170ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600
Code disassembly (best guess):
0: 4c 89 f2 mov %r14,%rdx
3: 48 c1 ea 03 shr $0x3,%rdx
7: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
b: 0f 85 93 05 00 00 jne 0x5a4
11: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
18: fc ff df
1b: 4c 8b 7b 40 mov 0x40(%rbx),%r15
1f: 49 8d 7f 1c lea 0x1c(%r15),%rdi
23: 48 89 fa mov %rdi,%rdx
26: 48 c1 ea 03 shr $0x3,%rdx

2a: 0f b6 14 02 movzbl (%rdx,%rax,1),%edx <-- trapping instruction
2e: 48 89 f8 mov %rdi,%rax
31: 83 e0 07 and $0x7,%eax
34: 83 c0 01 add $0x1,%eax
37: 38 d0 cmp %dl,%al
39: 7c 08 jl 0x43
3b: 84 d2 test %dl,%dl
3d: 0f .byte 0xf
3e: 85 .byte 0x85
3f: 57 push %rdi
==================================================================

The direct cause is that chunk->shkey is NULL in sctp_packet_bundle_auth().

	if (!chunk->auth)
		return retval;

	auth = sctp_make_auth(asoc, chunk->shkey->key_id);    <=== BUG
	if (!auth)
		return retval;

It is simple to fix it by adding a null-ptr check before sctp_make_auth() but maybe
there are better solutions?

Thanks.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.