From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f171.google.com (mail-qk1-f171.google.com [209.85.222.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BACCA36C5A9 for ; Fri, 31 Jul 2026 14:13:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785507197; cv=none; b=gel758ovxGDsXC10CUH/RIi/PBK7GdXXR0oRSZtYUmgYirVon3B6fs50PT/njV+4vYyKuJVcasAAEu9XIqCpbzTT0XPppN4MT3v35NO8UfAXiRqG3K1YyF0hMJZ1nnnTBnvCblTQkt7p/oA9AZq5sm2Z2xIoPry2CWofFYpyFCs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785507197; c=relaxed/simple; bh=f8y7zXkc0E+z17vAWKNmc1qHXMoOIjzNIagS2xro+PA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=f+YzWOSsOzdprGKng1yLgHSg+4vh2swTF+8wrgrQkkeWXkotIhqyqyr1WUQKyBQZOfssOBmaKhT2ppMJ/FyyqhkAX0JqgD4QktgVcJYGi28EhI9qZn5Xp23K2wvuIzDxDOdHpezYm3VJATIrLf8Kk6LgXsidWQXAkjLIEpnjcDk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=COehuNeP; arc=none smtp.client-ip=209.85.222.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="COehuNeP" Received: by mail-qk1-f171.google.com with SMTP id af79cd13be357-92e6c4a867cso70291385a.0 for ; Fri, 31 Jul 2026 07:13:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785507194; x=1786111994; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=b15F1a43UTMMEkb+LiO+nUB2piwvXEDFRceF2Ae9bdo=; b=COehuNePcr4mzzt6NJFfKzNcDTvtmcJepUijNCL+b+5/tIOyWJ9nxBQ++ln7/Sp1jU 7NlCfan2NjFxYle7qUXIUK/r/5gcEboPOybRVVbff4dLYjYmNcIr+0NhfsAKP0Xu0xHk Eyn09NMdiPPgw7RSQTyGXArduVN5qLG/y4DrQUUS/qAMYJMIskt4reP35dATfhG5gcUc Ip00YC/rSspwXkY3Rt+VvtHX0cJiAcGtn0++/apliJmwkwwRgS/jqDT4IpdTV5fb/3fO xjr68bn2q6RsadWtZ4PJcxnP/Y8zKh7IxoTbThKz2Pt3Ilx06KvFjx3fLLQvh2zyFGT9 p9kA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785507194; x=1786111994; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=b15F1a43UTMMEkb+LiO+nUB2piwvXEDFRceF2Ae9bdo=; b=Nag0e157UqKVVg36Jm/DreoyNU6bKdzO3RbnFjQxnUf/1rMbnPN7NENtmEehPhc3BC dCOZFbdOJTY7Z4v9b7D50vtH39T6VEtyk5qHH9oXKiCGNJbcOoeN2QZug4M3jTHbx6Wh 08dcyMluURshtMAh/28yYNGqf0QK48M1oHIHbx0WO/kZY7c5wDlvKh59n25Qqn4QWY/n Axs1bHPyhfqMb43HPdmlaZ0Mcug2e3hxiTEEu0MHwIfPKg+WkCQIplubJzQFB3RbIgaq +H4cT3q6KEz+gOgKM9rbEcTujLkrEkQLjdfV2XVD24uKfEX7Do2/lEO7I8BEjR91D07L P5Wg== X-Forwarded-Encrypted: i=1; AHgh+RoalnsQyccPAuZ2JBnk2NOyRY0EAX57TngFKN44UffIP+A3aIWkExComxh4I3jxovkAtuRoj2vnK87Otts=@vger.kernel.org X-Gm-Message-State: AOJu0YxWMcQDppIk6ko0zQOuzkB716k//fjAPE51d+6Ctyot+Aeq5V7h wymDLAXw5PcYKqq3X93TQ0aC6ErZA3yrb9M9/Jl9b2jx6FLbd/YutPgKZDVGNWo7jMYY2J95Ktg KxArQ X-Gm-Gg: AR+sD12ZAsqF9Y+83lVLkbGxr/rzB4xXA/bqnNNGdmRjFLGzUvvx/LZs7lt2uX+9BSZ wmui5A0wrZoIAgBmVaUChpSZIutXv6nv/ExTdNK/2rzAdSzVFyT2Iq/TbsbQ2ajVmnu79Uo3WbZ dzDqOZzdA3qnHOSpLv/qOVZd5J93LUZ9sGddBBibbbWnucLaO+N/sLX91quMVSTsnZHAhlCYR1V STo//9WfanPxWnIVtxEH+1ajw/jFH9R1l2qkHttDiBIJQt0fjyetZTp7/ImHKRC22ew2IX8K0fD DBgJVWonz+yzswSzd1jl34JHfEPdTpqxzhZ39hlmX3lQtSnZ3W16kc5CzIBuPMw9i8YJ2oQHcke quQU/dNE6nPSRTM4edjEEmgHT9RmiYG3iO0I6rlh4BYEX7Jev9hPO7nmM/W9ma9DsU9AJeHVt1b vCcXiYljXuhmyIWm91jUxxip8JQsXpV45+LD8pmx66at5iwVveP709i81EkixwQQh3aQ== X-Received: by 2002:a05:620a:4502:b0:92e:ea8d:5c89 with SMTP id af79cd13be357-934a0aa7617mr7941585a.40.1785507194331; Fri, 31 Jul 2026 07:13:14 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-9349bc52142sm63714885a.15.2026.07.31.07.13.13 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 07:13:14 -0700 (PDT) From: David Lee To: andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: David Lee , Kyle Zeng , Dominik 'Disconnect3d' Czarnota , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] vxlan: keep the last remote linked during FDB flush Date: Fri, 31 Jul 2026 14:13:10 +0000 Message-ID: <20260731141311.570187-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures. Fixes: c499fccb71cb ("vxlan: vxlan_core: Support FDB flushing by destination VNI") Cc: stable@vger.kernel.org Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber Signed-off-by: Kyle Zeng --- Trail of Bits has a reproducer for this bug that triggers a KASAN slab-out-of-bounds read in vxlan_snoop() and can share if needed. drivers/net/vxlan/vxlan_core.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c index d834a4865..a00df127d 100644 --- a/drivers/net/vxlan/vxlan_core.c +++ b/drivers/net/vxlan/vxlan_core.c @@ -3058,6 +3058,11 @@ vxlan_fdb_flush_match_remotes(struct vxlan_fdb *f, struct vxlan_dev *vxlan, if (!vxlan_fdb_flush_remote_matches(desc, rd)) continue; + if (list_is_singular(&f->remotes)) { + *p_destroy_fdb = true; + return; + } + vxlan_fdb_dst_destroy(vxlan, f, rd, true); remotes_flushed = true; } -- 2.53.0