mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: [PATCH net 1/2] vti: fix tunnel device use-after-free across async crypto resumption
       [not found]   ` <179110850671.434549.2584497019282941556@kernel.org>
@ 2026-10-08  1:49     ` Qihang
  0 siblings, 0 replies; only message in thread
From: Qihang @ 2026-10-08  1:49 UTC (permalink / raw)
  To: netdev
  Cc: David Ahern, Ido Schimmel, Steffen Klassert, Herbert Xu,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, linux-kernel

All real, and vti6 has the same problems.

The dev_hold()/dev_put() idea assumed the callback runs exactly once
per skb, which xfrm_input() doesn't guarantee. IPTFS frees the outer
skb on its own without any callback. The early drop when the SA is no
longer valid happens while family is still AF_UNSPEC, so xfrm_rcv_cb()
can't find the afinfo and never calls us. And on the success path I'd
drop the last reference before gro_cells_receive() is done with
skb->dev.

So I'll drop this. Two options I can see for the respin:

Re-lookup the tunnel in the callback like xfrmi does. The only key I
have there is the outer addresses of the state, which won't reproduce
the original lookup for wildcard-source SAs, and during teardown it
can pick up the fallback device instead. The RCU section also ends at
gro_cells_receive(): the skb queued to the gro cell is processed by
NAPI afterwards with skb->dev still pointing at the tunnel device and
nothing holding a reference.

Keep a reference from vti_input() but release it when the skb is freed
instead of in the callback, so the paths where the callback never runs
can't leak. That looks like it needs xfrm core support, so I'd rather
not pick it unilaterally.

Which way do you want this to go?

pw-bot: cr


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-08  1:49 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <20260930090813.73901-1-q.h.hack.winter@gmail.com>
     [not found] ` <20260930090813.73901-2-q.h.hack.winter@gmail.com>
     [not found]   ` <179110850671.434549.2584497019282941556@kernel.org>
2026-10-08  1:49     ` [PATCH net 1/2] vti: fix tunnel device use-after-free across async crypto resumption Qihang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®