From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f174.google.com (mail-qt1-f174.google.com [209.85.160.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ABBD33E557D for ; Mon, 13 Jul 2026 09:59:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783936764; cv=none; b=pPVvuyT3K85x9jq45CItt4O1bpQSq8kfts2LU7pqxYBBHy6HH+xjeoP/VKoGrKYwwSFBMaUoygzQHhYxBR3RKmgr98WYhkO+6L9xdIkVrFFSOXbww7JCxNu2PgpSBLSKfpiIan5xsTCbZ1g8e08QOS63mcKvPcZcPw22gCLsCx8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783936764; c=relaxed/simple; bh=LA7wMZh7wJW7zKJdgEo3kzYUfAFMoTptp6YhxtUQJcs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=POLTYhpILYYBt2/Jpng256IOyeH40qNwAYwxmSrdfBAWUBfxBQvAud3Gy9Ra4KxFmpWbxFOBOC4+7+t+5t2IL199/KDYdKxiupfrZiqZb2ewp4YSIZUY4FwQ8JQVNESllFnNW12sJe3aZgXxpJGiFKjePAG/LLgyoLU1cJTXJbc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=LUa/Gu5Z; arc=none smtp.client-ip=209.85.160.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="LUa/Gu5Z" Received: by mail-qt1-f174.google.com with SMTP id d75a77b69052e-51c05dcdf49so32213301cf.0 for ; Mon, 13 Jul 2026 02:59:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1783936762; x=1784541562; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=hs8qr6RQnmSpKBHIaxXg7wFtv+zX+5SylTG991lre7o=; b=LUa/Gu5Z0UVW9aZ8Jpz8/b+NV0/eoLRG0rQW7D0/u589VSrlz6O0K41WR9ABdezT8i UqIKlft/nFeNNV0BO01TEC5auY3zXWpCRM6gSmIqpR5wAQO3WtIacTpvjOldoyzH+SlX P9vD0OMeovfEwpW6w5FDH/BIBUSrKq9qhwxTLziZLw6GRe7qLZE0N1IqkF2zqE8uM/yH KVQ3PNUNlI4UeUuqn9QDgRpUtRMFrdIXnnSFzc/Nq/cTB3XhTgmhwhAHDAeV0Pn1aKbb FgBsMFOESSDlLQnX99Rqy+d9A34FpBjZIhFYPr3h6v2FHK/9P/OwLxC/TzE1etFjXQfY vcHg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783936762; x=1784541562; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hs8qr6RQnmSpKBHIaxXg7wFtv+zX+5SylTG991lre7o=; b=aRirz1F/EV5ZYlYeiX0x+pCvY7A72NHLSN79qaBMasIYKR/xGT3LTuG0aanpvcer/u xEltzEcpG7nrbs46lyYIj2aXaUmRtxT3YeObucYB7RqykZJhwI6cvUIEq6cF1KGXghdp 8Gogcx+LW+AZ7dGOjHR8ePNGvgVbA4Fp8HQoNnNNJ8jEmsrqSupgwgzBX1rbNuFeNOz2 fCg55m+2TRQbozIgRs0OrH6sgYgMtoiK/GSswFwth+NVQhyAIPxLbREO6nRbB54DdmMb cwX8IkBn99B0LIfBGZt+enABJqkgg190SM+vtu4XO46ZtfG5fgZTWqAd2Ec+x0x2mEJ1 OxLg== X-Forwarded-Encrypted: i=1; AHgh+RoYdySR7YpH82d1oEBkeI8T0F5mpeQHWPSsR+NgY8DC/pKlJYDpdSlsn974u8Au/+uOxtlYlmguyH/q/Ic=@vger.kernel.org X-Gm-Message-State: AOJu0Yzw7ilqLZQmhaZO2VeRnw9oWm1XbprEjN9QGGykVUtKPjk/4fuk D62YjCPEhrhxpZQtrAfX2TbndAK8lodzwk3sEa8mVh9T4uY508Z229r2KL4RzHAhZ5I= X-Gm-Gg: AfdE7cnhWvLh75lgW6tsoIjUv6a3/sOCwPk5DCOPVUO72oFdWtdyXoCXRdzFC38l38V Ms7wEz7vb4uNGjBxqD8WG20kOWky2J+7ndYzK3X8weHYWxyK5dPqEKzzrUa5AIy5lXQ4BbTKrzE t/SGszXLcKW6iwRO75UtVFQI+OxS43p7scMZLd3/bMXq7VbOIiXH+Yi2qylvF9P+jHm3VcrS+Tq ehdFTAdgTNKiSEJo91XkG7fJitFdOK/cZWEbbx9oyzgVeHCeg4oWlye2TbOtv8lWR/PfaVw8+6o PqA0QLMO+kPpRkbSdtgWN5YxZKKpJua51KMRt3CFxCxDwZHDrudG2LKbfyvQJabzHGrQyIzI0/l hbbnGCUCJfcdRDDwpK85n7H1I259nm3AjjrtdRW3jS9ADt4bVQmIB7FO/f5/lq8EwNb5axyRlO4 me8PKQL9h+d8NvZ1dE+Fy71eLuJ1vU X-Received: by 2002:ac8:7d0e:0:b0:51c:7b12:5fd5 with SMTP id d75a77b69052e-51cbf349147mr86478831cf.81.1783936761618; Mon, 13 Jul 2026 02:59:21 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id d75a77b69052e-51caae20a40sm80619171cf.15.2026.07.13.02.59.21 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 13 Jul 2026 02:59:21 -0700 (PDT) From: David Lee To: Pablo Neira Ayuso Cc: David Lee , Florian Westphal , Jozsef Kadlecsik , Phil Sutter , Dominik 'Disconnect3d' Czarnota , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH nf] netfilter: ipset: do not update comments from kernel-side hash adds Date: Mon, 13 Jul 2026 09:59:15 +0000 Message-ID: <20260713095918.173450-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit mtype_resize() copies comment pointers with memcpy(), not the comment objects themselves. During the window after an entry has been copied but before the table swap and backlog replay, the old table is still published for packet-side updates while the replacement-table entry already holds the same ip_set_comment_rcu pointer. If xt_SET --add-set ... --exist hits that old entry in this window, mtype_add() calls ip_set_init_comment() even though packet-side adds carry no comment payload. That call frees the shared comment through the old entry, so the replacement-table entry now holds a stale pointer. When the queued add is replayed on the new table, mtype_add() calls ip_set_init_comment() again and strlen() dereferences the stale pointer. Fix this in mtype_add() by skipping ip_set_init_comment() when ext->target marks a packet-side add. Userspace adds still update comments, while packet-side adds can no longer free comment storage shared with a resize copy. Fixes: f66ee0410b1c ("netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports") Cc: stable@vger.kernel.org Signed-off-by: David Lee Assisted-by: Codex:gpt-5.5 --- A reproducer triggers a KASAN slab-use-after-free in strlen() from ip_set_init_comment() during hash_ip4_resize(). Trail of Bits has a privilege escalation PoC for this bug on a custom kernel, which can be shared further if needed. net/netfilter/ipset/ip_set_hash_gen.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h index 8231317b0f1f..b2d77973272d 100644 --- a/net/netfilter/ipset/ip_set_hash_gen.h +++ b/net/netfilter/ipset/ip_set_hash_gen.h @@ -1005,7 +1005,7 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext, #endif if (SET_WITH_COUNTER(set)) ip_set_init_counter(ext_counter(data, set), ext); - if (SET_WITH_COMMENT(set)) + if (SET_WITH_COMMENT(set) && !ext->target) ip_set_init_comment(set, ext_comment(data, set), ext); if (SET_WITH_SKBINFO(set)) ip_set_init_skbinfo(ext_skbinfo(data, set), ext); -- 2.43.0