From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 24BEF3328FD for ; Tue, 4 Aug 2026 06:10:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785823803; cv=none; b=aEBsBsYLucx23sQnj/znAz4fGNT/9x0JPTVY1+kOxyH8mdSqh3fAZEc5AMNPrbday8wD98tS2JtebpY9XtbmbNWJ24GnnK38eGTOrsKwsBWaeqwkvyyPzzd4v0x94jv0+VqR5CnDkN0UBqSFA1Y2b9i5PFp01hI40KgS4dA3q4A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785823803; c=relaxed/simple; bh=hoBcQLufPj2/EG+NglGciSArXHLoJN4T/RIwQYNKVmw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=RCru4uZjNTfFjBdQhBzHGNO5w/V8sNO96t3MVC7BDByClLTO93oBEnC5FAB35oJCXIvcAIph17aVVvuujpoetshNP4Ujc0kNZ5b4KwHH8WzrM60z8u5z7zCUy5WwGmKKx+tO1GWGV20+B/Qocm1PK4iso2d/Lp2d06Gb5AyAy3Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=kPlDBj90; arc=none smtp.client-ip=209.85.219.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="kPlDBj90" Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-8eeb4508f29so28990436d6.0 for ; Mon, 03 Aug 2026 23:10:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785823800; x=1786428600; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=C9tpyP4DZI5UiWip+9VyOdslieTAF/jyWhJQO7HCZHE=; b=kPlDBj90P3bbhP5+hnQjotXEoVzY65HhP+a1ZX2RHToahUmoRON5fyq+/1ma9Dweti LRWeoKY5K7vyJirBK3XNBhXOdTWdRx3ONh4eeVjx3meCpo1iJxOTbrA+SRqyhe96f9Eq xw43oX0bfaq96PtJxvvszcg3Fve8f+JzTvleAnyRgofwyKDXC30yJW14e+4b3ev1yZF0 +Qskbn7natNW4PVq+ZnWvZKhXe1jGGkewPrLQC9KCMTjYYzhVHnxf4PxRYhu6jQLh87i 72rDqa+NmgeNWXM78de103TIt3T8i0meMTYQ6g4slVagrcictYgDOH+pDHt/DSOCyyYY 6Jkw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785823800; x=1786428600; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=C9tpyP4DZI5UiWip+9VyOdslieTAF/jyWhJQO7HCZHE=; b=jnGiXln3P9q8Jr4THu80iGbSK+9pHkbpvtWX27xfiSwZUM5LvSyILopoxRmhGlMjhW XdUC/48bZja0p8idftU1kqw9TqJ+X8RkFjtAZCohaMJQUAhyHaaqf+d3G3pNSUZWamNv p3mZ3xNUD2GVmm3+hFMjAnPeCc13/PxioD75mbYGxl+ToVigPjeqBQLoTSHqDVrC9kWr p6WaoCaVKlmdB9o0AhTMHtNV1hOM+PWXvpex4q9LZgqaX7YEid4+D15l6Y84b1bflw8F yMG8wnQ9ybxJaxsrEIe90Dx7+8MTlDEYlslx1LkCl2eG4ZiO4ZAq/XJC1lzqwk8L2C6s DYvw== X-Forwarded-Encrypted: i=1; AHgh+Rp+tMtsoAUdf+NIDgjuKB4SQ/4XfQOS67+78K39k7Z/lxAVGnG/ZCbhyf8waFkS5lqOrCHCfvZr5Kl3FZs=@vger.kernel.org X-Gm-Message-State: AOJu0Yz+WJHXuroxxjSEQIIjzfO1PqoASCAZgAiUOm//q1Q0WXuJcCWx M3We7A8Qvp9+gyRidwd1cvCdkX95Y0D8B/Ham321St7KIxAQ2k5QtSRIk+Pj0oBNTfc= X-Gm-Gg: AR+sD136TnjV2qECwf9WAhtFTZwT9GuZLwiHket6u/IFzHOJhubWY3yE3zHxjzuzJTp bcs2GMghodnJdhgxav5nO3HOcjRLUJ3Er6xG3hkyRj1Kkj7IuQZ4nHmP8y5kHBQn+HzKBQ875KH nxGScus4wU+9qXhOE0TfPbjNDw77kG/lhDaKhc0zpCOCHwiKL9vll4/Zk2KuiCZzOKf4K9DLFy+ 4QsSPgcnXTNKTDYU6rqUnq4F3wasLxldtc5AxhinMRSkgvIyUcy4hbk5YivF7qdQMiisIrJu3Q0 h72pHUtcj6z5oXaat4FOs/Gkk4brgBNK2t+MfXS6M8uAC6Enwyj9t8cHjAKYkrqqOa96sTGF+VM bcMeUrGTeorlc7VC9CeUKf3yw1C/jqYqX9CYGJvWcgow6AeuaG4NXhfC9Npx6sVYJ19c+RTFVJI Ap/H/r1dI/XuJZdqY2no9599V8fZs082Fw48GYvFCyc4/FRxsEiDGpQcy6XfUXORT0YQ== X-Received: by 2002:a05:620a:2792:b0:92e:e125:55bb with SMTP id af79cd13be357-934a0750096mr2572674085a.4.1785823800003; Mon, 03 Aug 2026 23:10:00 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908432a0cb9sm93059666d6.7.2026.08.03.23.09.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 03 Aug 2026 23:09:59 -0700 (PDT) From: David Lee To: andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , Sven Eckelmann , Petr Machata , Amit Cohen , Ido Schimmel , Kuniyuki Iwashima , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Lee Subject: [PATCH net v2] vxlan: keep the last remote linked during FDB flush Date: Tue, 4 Aug 2026 06:09:58 +0000 Message-ID: <20260804060958.711335-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Kyle Zeng A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures. Fixes: c499fccb71cb ("vxlan: vxlan_core: Support FDB flushing by destination VNI") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber Signed-off-by: Kyle Zeng Co-developed-by: David Lee Signed-off-by: David Lee --- Changes in v2: - Add the net tree prefix to the subject. - Restore Kyle Zeng as the patch author and correct the sign-off chain. - Move the research credit below the commit-message separator. - Add the recipients reported by netdev CI. v1: https://lore.kernel.org/all/20260731141311.570187-1-david.lee@trailofbits.com/ Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Trail of Bits has a reproducer for this bug that triggers a KASAN slab-out-of-bounds read in vxlan_snoop() and can share if needed. drivers/net/vxlan/vxlan_core.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c index d834a4865..a00df127d 100644 --- a/drivers/net/vxlan/vxlan_core.c +++ b/drivers/net/vxlan/vxlan_core.c @@ -3058,6 +3058,11 @@ vxlan_fdb_flush_match_remotes(struct vxlan_fdb *f, struct vxlan_dev *vxlan, if (!vxlan_fdb_flush_remote_matches(desc, rd)) continue; + if (list_is_singular(&f->remotes)) { + *p_destroy_fdb = true; + return; + } + vxlan_fdb_dst_destroy(vxlan, f, rd, true); remotes_flushed = true; } -- 2.53.0