Re: [PATCH net] ipv4: fix use-after-free in fib_nhc_update_mtu()

David Ahern <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On 7/31/26 10:29 AM, Chengfeng Ye wrote:
> fib_nhc_update_mtu() walks the nexthop exception table under RTNL, but
> RTNL does not serialize this walk with PMTU exception updates. The walk
> uses rcu_dereference_protected() with a constant true condition without
> holding either fnhe_lock or an RCU read-side critical section.
> 
> The following interleaving can therefore occur:
> 
>   CPU 0                              CPU 1
>   fib_nhc_update_mtu()               update_or_create_fnhe()
>     load fnhe                          spin_lock_bh(&fnhe_lock)
>                                        fnhe_remove_oldest()
>                                          unlink fnhe
>                                          kfree_rcu(fnhe, rcu)
>     <quiescent state>
>     access fnhe after grace period
> 
> KASAN reported:
> 
>   BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410
>   Read of size 8 at addr ffff888107d49000 by task poc/90
>   Call Trace:
>    fib_nhc_update_mtu+0x3df/0x410
>    fib_sync_mtu+0x7a/0xd0
>    fib_netdev_event+0x229/0x3f0
>    netif_set_mtu_ext+0x33a/0x570
>    dev_set_mtu+0x88/0x120
>   Allocated by task 89:
>    update_or_create_fnhe+0xa80/0x1110
>    __ip_rt_update_pmtu+0x8f2/0xcd0
>    ipv4_sk_update_pmtu+0x49e/0x690
>    udp_err+0xd92/0x1080
>   Freed by task 0:
>    __kasan_slab_free+0x43/0x70
>    kvfree_rcu_cb+0x12f/0x420
>    rcu_core+0x509/0x18e0
> 
> Protect the full walk with rcu_read_lock() and use rcu_dereference()
> for the RCU-published pointers. This prevents reclaim from completing
> until all references held by the walk have been dropped, without
> serializing PMTU updates against the entire hash-table traversal.
> 
> Fixes: af7d6cce5369 ("net: ipv4: update fnhe_pmtu when first hop's MTU changes")
> Cc: [email protected]
> Signed-off-by: Chengfeng Ye <[email protected]>
> ---
>  net/ipv4/fib_semantics.c | 11 +++++++----
>  1 file changed, 7 insertions(+), 4 deletions(-)
> 

Reviewed-by: David Ahern <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.