From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from www62.your-server.de (www62.your-server.de [213.133.104.62]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2EFEE2DECBA; Thu, 28 May 2026 22:28:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=213.133.104.62 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780007295; cv=none; b=ocdtPnF/PRuI6Mtol0sa3CPpVcXcGEkPIbeTcDQCwzN0KNDxOEmJ8koSVtZEEMJHus+aIV3lsfny3uHfHPAvhVrO1icKNnq09NXDK3d6He9qeUb3yVWW2jbFALFJnBO9xiH1xvhszJPYziGBm48Det02mRI05BL1K27lCK+lLiE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780007295; c=relaxed/simple; bh=NSgBkh4h1m3GUmstvliXoCMJgzLxdw2XD4GaDjxNcWQ=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=s0zfx+z9iyRUtYNjJcK2OHCy+xiLe6kaefP+lAK7QF++VF4pONtPCqQsZ8HVoGfwmQdttPH/dL3BsbDgTcELWaptjE7mrD8R5hgKKOQzAtA2FTzB9H7UhZM1C2H/pxMHOzwnbNxVkP3fb6weENzF5pElac1Yo/ieouUcAMLLPwE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=iogearbox.net; spf=pass smtp.mailfrom=iogearbox.net; dkim=pass (2048-bit key) header.d=iogearbox.net header.i=@iogearbox.net header.b=Mzn87fUh; arc=none smtp.client-ip=213.133.104.62 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=iogearbox.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iogearbox.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=iogearbox.net header.i=@iogearbox.net header.b="Mzn87fUh" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=iogearbox.net; s=default2302; h=Content-Transfer-Encoding:Content-Type: In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date:Message-ID:Sender :Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID; bh=TMBNnpFYJcb4ZYyve5TiuyUrZJ4esed3534C/01rFcg=; b=Mzn87fUhHYqrrM7BIE4PRCYGJc IqiQe1lRra6f+zYwABXVTPYSuudnSHm9NTb60Us3I3skZ0EIVK2M5ERdTyoSQodOGBn38H7HCKN3Z +P+tqSOdDpvaUj1I+QOl4yPxjiCBXK8Sv9fpaW78ryqZs8ZTeqQrWh7OQASwzZJnUWQxln3uVKwTr DVPzN8Rh0eqnH5SeNNB3v2zgU0gomPY3xnHtpc1B5qIIJUKHAbSqcI+HwtUJ+FFr41pUWKc+BTe2i 7MmAL7Pw6+Jr0L8sNJzm/l+PdSqpeXkpX2dt3YTrvOX4PUG9FblmFdV58dBUJOUX9tvaTE+hwepZj oOAhaKaw==; Received: from sslproxy06.your-server.de ([78.46.172.3]) by www62.your-server.de with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96.2) (envelope-from ) id 1wSjCu-000Fci-2p; Fri, 29 May 2026 00:28:04 +0200 Received: from localhost ([127.0.0.1]) by sslproxy06.your-server.de with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wSjCt-000H1F-2x; Fri, 29 May 2026 00:28:04 +0200 Message-ID: <14ca7b06-55bd-497d-b1ef-bcb95d1fe2ca@iogearbox.net> Date: Fri, 29 May 2026 00:28:03 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Linux: DMA-after-unmap race in ZCRX via netif_rxq_cleanup_unlease() ordering inversion (netkit + page_pool) To: Jakub Kicinski , =?UTF-8?Q?Pr=C3=A9nom=3F_Ahmed?= Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, David Wei References: <20260527163320.407b4af1@kernel.org> Content-Language: en-US From: Daniel Borkmann Autocrypt: addr=daniel@iogearbox.net; keydata= xsFNBGNAkI0BEADiPFmKwpD3+vG5nsOznvJgrxUPJhFE46hARXWYbCxLxpbf2nehmtgnYpAN 2HY+OJmdspBntWzGX8lnXF6eFUYLOoQpugoJHbehn9c0Dcictj8tc28MGMzxh4aK02H99KA8 VaRBIDhmR7NJxLWAg9PgneTFzl2lRnycv8vSzj35L+W6XT7wDKoV4KtMr3Szu3g68OBbp1TV HbJH8qe2rl2QKOkysTFRXgpu/haWGs1BPpzKH/ua59+lVQt3ZupePpmzBEkevJK3iwR95TYF 06Ltpw9ArW/g3KF0kFUQkGXYXe/icyzHrH1Yxqar/hsJhYImqoGRSKs1VLA5WkRI6KebfpJ+ RK7Jxrt02AxZkivjAdIifFvarPPu0ydxxDAmgCq5mYJ5I/+BY0DdCAaZezKQvKw+RUEvXmbL 94IfAwTFA1RAAuZw3Rz5SNVz7p4FzD54G4pWr3mUv7l6dV7W5DnnuohG1x6qCp+/3O619R26 1a7Zh2HlrcNZfUmUUcpaRPP7sPkBBLhJfqjUzc2oHRNpK/1mQ/+mD9CjVFNz9OAGD0xFzNUo yOFu/N8EQfYD9lwntxM0dl+QPjYsH81H6zw6ofq+jVKcEMI/JAgFMU0EnxrtQKH7WXxhO4hx 3DFM7Ui90hbExlFrXELyl/ahlll8gfrXY2cevtQsoJDvQLbv7QARAQABzSZEYW5pZWwgQm9y a21hbm4gPGRhbmllbEBpb2dlYXJib3gubmV0PsLBkQQTAQoAOxYhBCrUdtCTcZyapV2h+93z cY/jfzlXBQJjQJCNAhsDBQkHhM4ACAsJCAcNDAsKBRUKCQgLAh4BAheAAAoJEN3zcY/jfzlX dkUQAIFayRgjML1jnwKs7kvfbRxf11VI57EAG8a0IvxDlNKDcz74mH66HMyhMhPqCPBqphB5 ZUjN4N5I7iMYB/oWUeohbuudH4+v6ebzzmgx/EO+jWksP3gBPmBeeaPv7xOvN/pPDSe/0Ywp dHpl3Np2dS6uVOMnyIsvmUGyclqWpJgPoVaXrVGgyuer5RpE/a3HJWlCBvFUnk19pwDMMZ8t 0fk9O47HmGh9Ts3O8pGibfdREcPYeGGqRKRbaXvcRO1g5n5x8cmTm0sQYr2xhB01RJqWrgcj ve1TxcBG/eVMmBJefgCCkSs1suriihfjjLmJDCp9XI/FpXGiVoDS54TTQiKQinqtzP0jv+TH 1Ku+6x7EjLoLH24ISGyHRmtXJrR/1Ou22t0qhCbtcT1gKmDbTj5TcqbnNMGWhRRTxgOCYvG0 0P2U6+wNj3HFZ7DePRNQ08bM38t8MUpQw4Z2SkM+jdqrPC4f/5S8JzodCu4x80YHfcYSt+Jj ipu1Ve5/ftGlrSECvy80ZTKinwxj6lC3tei1bkI8RgWZClRnr06pirlvimJ4R0IghnvifGQb M1HwVbht8oyUEkOtUR0i0DMjk3M2NoZ0A3tTWAlAH8Y3y2H8yzRrKOsIuiyKye9pWZQbCDu4 ZDKELR2+8LUh+ja1RVLMvtFxfh07w9Ha46LmRhpCzsFNBGNAkI0BEADJh65bNBGNPLM7cFVS nYG8tqT+hIxtR4Z8HQEGseAbqNDjCpKA8wsxQIp0dpaLyvrx4TAb/vWIlLCxNu8Wv4W1JOST wI+PIUCbO/UFxRy3hTNlb3zzmeKpd0detH49bP/Ag6F7iHTwQQRwEOECKKaOH52tiJeNvvyJ pPKSKRhmUuFKMhyRVK57ryUDgowlG/SPgxK9/Jto1SHS1VfQYKhzMn4pWFu0ILEQ5x8a0RoX k9p9XkwmXRYcENhC1P3nW4q1xHHlCkiqvrjmWSbSVFYRHHkbeUbh6GYuCuhqLe6SEJtqJW2l EVhf5AOp7eguba23h82M8PC4cYFl5moLAaNcPHsdBaQZznZ6NndTtmUENPiQc2EHjHrrZI5l kRx9hvDcV3Xnk7ie0eAZDmDEbMLvI13AvjqoabONZxra5YcPqxV2Biv0OYp+OiqavBwmk48Z P63kTxLddd7qSWbAArBoOd0wxZGZ6mV8Ci/ob8tV4rLSR/UOUi+9QnkxnJor14OfYkJKxot5 hWdJ3MYXjmcHjImBWplOyRiB81JbVf567MQlanforHd1r0ITzMHYONmRghrQvzlaMQrs0V0H 5/sIufaiDh7rLeZSimeVyoFvwvQPx5sXhjViaHa+zHZExP9jhS/WWfFE881fNK9qqV8pi+li 2uov8g5yD6hh+EPH6wARAQABwsF8BBgBCgAmFiEEKtR20JNxnJqlXaH73fNxj+N/OVcFAmNA kI0CGwwFCQeEzgAACgkQ3fNxj+N/OVfFMhAA2zXBUzMLWgTm6iHKAPfz3xEmjtwCF2Qv/TT3 KqNUfU3/0VN2HjMABNZR+q3apm+jq76y0iWroTun8Lxo7g89/VDPLSCT0Nb7+VSuVR/nXfk8 R+OoXQgXFRimYMqtP+LmyYM5V0VsuSsJTSnLbJTyCJVu8lvk3T9B0BywVmSFddumv3/pLZGn 17EoKEWg4lraXjPXnV/zaaLdV5c3Olmnj8vh+14HnU5Cnw/dLS8/e8DHozkhcEftOf+puCIl Awo8txxtLq3H7KtA0c9kbSDpS+z/oT2S+WtRfucI+WN9XhvKmHkDV6+zNSH1FrZbP9FbLtoE T8qBdyk//d0GrGnOrPA3Yyka8epd/bXA0js9EuNknyNsHwaFrW4jpGAaIl62iYgb0jCtmoK/ rCsv2dqS6Hi8w0s23IGjz51cdhdHzkFwuc8/WxI1ewacNNtfGnorXMh6N0g7E/r21pPeMDFs rUD9YI1Je/WifL/HbIubHCCdK8/N7rblgUrZJMG3W+7vAvZsOh/6VTZeP4wCe7Gs/cJhE2gI DmGcR+7rQvbFQC4zQxEjo8fNaTwjpzLM9NIp4vG9SDIqAm20MXzLBAeVkofixCsosUWUODxP owLbpg7pFRJGL9YyEHpS7MGPb3jSLzucMAFXgoI8rVqoq6si2sxr2l0VsNH5o3NgoAgJNIg= In-Reply-To: <20260527163320.407b4af1@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Virus-Scanned: Clear (ClamAV 1.4.3/28014/Thu May 28 08:24:59 2026) Hi Ahmed, On 5/28/26 1:33 AM, Jakub Kicinski wrote: > Dropping security lists, security lists are for private discussions, > it's utterly pointless to CC both them and LKML. Not to mention > that this bug only exists in -rc kernels. > > Adding relevant developers. Moving security@ to Bcc Thanks for the report! I think a fix could look as below. Before submitting, I would prefer though if David could check this against real HW supporting mem providers e.g. BCM NIC: diff --git a/net/core/netdev_rx_queue.c b/net/core/netdev_rx_queue.c index de4dac4c88b3..00a7011eb4d5 100644 --- a/net/core/netdev_rx_queue.c +++ b/net/core/netdev_rx_queue.c @@ -338,12 +338,12 @@ void __netif_mp_uninstall_rxq(struct netdev_rx_queue *rxq, void netif_rxq_cleanup_unlease(struct netdev_rx_queue *phys_rxq, struct netdev_rx_queue *virt_rxq) { - struct pp_memory_provider_params *p = &phys_rxq->mp_params; unsigned int rxq_idx = get_netdev_rx_queue_index(phys_rxq); + struct pp_memory_provider_params p = phys_rxq->mp_params; - if (!p->mp_ops) + if (!p.mp_ops) return; - __netif_mp_uninstall_rxq(virt_rxq, p); - __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p); + __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, &p); + __netif_mp_uninstall_rxq(virt_rxq, &p); } > On Wed, 27 May 2026 23:53:45 +0100 Prénom? Ahmed wrote: >> Hello, >> >> I would like to report a source-proven teardown ordering bug in the Linux >> kernel that can lead to a DMA-after-unmap race condition involving ZCRX >> (io_uring zero-copy receive), page_pool, and netkit queue leasing. >> >> ***Reporter:** Ahmed Abdelmoemen **Discovery Date:** 2026-05-26 **Kernel >> Version:** Linux 7.1.0-rc3* >> >> Executive Summary >> >> *A logic error in `netif_rxq_cleanup_unlease()` causes DMA mappings for the >> ZCRX memory provider to be revoked **before** the physical NIC RX queue is >> stopped. This creates a race window during netkit queue lease teardown >> where the physical device's NAPI can consume stale `net_iov` entries from >> the page_pool alloc cache containing `dma_addr = 0`.* >> >> The ordering inversion is fully proven at the source level. However, I have >> **not** performed runtime verification, so actual memory corruption or >> successful DMA to address 0 has **not** been proven — it remains hardware >> and driver dependent. >> >> The bug is reachable with `CAP_NET_ADMIN` (common in container >> environments) when using netkit with ZCRX. >> >> Root Cause >> >> In `net/core/netdev_rx_queue.c:347-348`: >> >> ```c __netif_mp_uninstall_rxq(virt_rxq, p); // DMA unmap + dma_addr=0 >> __netif_mp_close_rxq(...); // queue stop + NAPI disable (TOO LATE) >> >> This inverts the correct ordering used in normal device unregistration and >> io_uring close paths (stop first, then unmap). >> Impact >> >> - *Potential:* NIC DMA write to physical address 0 (or stale mappings >> with lazy IOMMU) leading to memory corruption. >> - *Requirements:* CAP_NET_ADMIN + netkit queue leasing + ZCRX installed >> on the leased queue. >> - *Current Status:* No runtime PoC or crash reproduction yet. The race >> window exists in theory but its practical exploitability needs confirmation. >> >> I am attaching the full detailed analysis. >> Proposed Fix[image: image.png] >> >> I am happy to provide more details or assist with testing.