From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4CD0148CD56 for ; Wed, 19 Aug 2026 16:59:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787158775; cv=none; b=CMMKnRpSiNuApv0tbPUDY7oqNzc33/EhwvKa0b1VzdMwWuKcStQGKT+NIIna896w6O0WLB7iJ7fYNvXa5/m1r0xlL9v7OusSctrSEikmmr5E/9+ZmQDRhQrbwR0UsOWZ41iMS/Ryq6Irha0HUQb1lK9AbJa9zGYYnnhDlxSJ/p0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787158775; c=relaxed/simple; bh=2XaBdkgJgruoXsAicUbM+D98FdFgxNckiG2SMl4ao5I=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DmJ6nI1MUAmb9d/QcA2eRQXaejywj1Qu0Fux1x3W6BRfSFGVFMZ2e7YZNKON2KfFHvMqF/soxZEEDSXvYzlkNzYM+8Jg7PqUmDEC6spcah/opRaev5w1vHtN21ccmfyQMTV0WlXdCXFOKy1AcqAUcHzaTQeX5H4cnrEKuSJT8XA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=ZEhG+p1+; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="ZEhG+p1+" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-84862b0d5aeso1250456b3a.2 for ; Wed, 19 Aug 2026 09:59:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1787158771; x=1787763571; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=lroOjWUQuzkzfsFV8jZnR6n9nf3kSNRY1PDaEZgo3rY=; b=ZEhG+p1+JhbCtDFNGxIAUWYD5ca0Am1hyiyjKbYarH7pP8hPyMVKTTPtuJ9Onu1/eF PvT5WLh2M5j5c0ymfbXVlgoXIQ0jVb2NWHArvDvt1QqwVllR/dD5WNl11HYl6v4cgW1E kJzP9C6owIloPbytN0Bq5RnMH7g2pJLHVd1XzUmeE1PsYfwrVovA3p0pGAfFZ6sxEiIQ A5OqUR5GzpTxfMFadIQtWl2mZX10VqOduxPgUL9kwj6OciZcG1COCEZHd+8ISKz2b3yR yBn5floZcmPhUc8QC+y7/e+VI6w6WGVn6rQxi7ffzCjinq5YHCpoK+EFaOATTtteOVfX vi8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787158771; x=1787763571; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lroOjWUQuzkzfsFV8jZnR6n9nf3kSNRY1PDaEZgo3rY=; b=GUGzRtVHi2AFz0Ivj6HyGDKk440rDYznfAUUYLQYILmDytZc/I2/G0k8BGEGolqbKQ 3L97BBQm0x+HQYutSmOC/nkrGOar0yWm9Mv1kETdRbvwNpmfzrkGwIE+ZF2RwhJuwLwz DF4BNVSeaEeaaK6UfNBhIbriTpTRa2MZd13I06hkgYzWixoJsnjiRsAv6SrXvtVrCXhZ iRYU70P7LuMriBQEQvEI/UVboALZVz5wGesyXEP77S92NpYfAu2rO4OpXZV3KwviRvoA uM4szlU5XibXesc4KCcrmRCyrAULfsx/lxAcGqLXww5gIRea5NcFptIzl5s0AEp4jA6a kC5g== X-Forwarded-Encrypted: i=1; AHgh+RrSWkls63CdiBODE0drZ6qp5KJdhcO+zDcrSfRJ6cJi3J01312D/NXSMyMeswe6bpck2oYz9MMsot4IKIw=@vger.kernel.org X-Gm-Message-State: AOJu0Yy7If2e/jDCp6nDa9CAHz3tXDU2nTHoM98+w+AW/ehUE78T7y0d 4ImkIqCTWobV/m8fObyb8BPWC3Okfua5tCM7WPfd1kBG0OwWZ77O1dkB0f3yEolxRJc= X-Gm-Gg: AR+sD11LR1QzANbnMI1vjVHALWdwrTMd8k2s3riSGyUbQlwFqnzYMJ1xUjjcH7SolQz Af8hSZYMNN670p6RZBk5tRIJpw54aDt1cxrr1UmkKkFyLucFQ5hfWgUESARFSKzS7yZQ18iw/ai 0wO7vbJVWM59qfD2Mmu1Z1KKZwHSy0frKbMaQse/j0dKVp693II79fbStGRUT/vg6C39OciZRM/ Sety05PsBxx2DMduv6q7ugDgGmYUuCncIoxEBh/i1BbGCuqK4lR8FN7h5UTmOgmr3wTWzsZJxl9 MpVnNMAV1u8/y804/P0dtu/hGhnBGkWhdSTkWqHMkiSbyEtBiHmndPVZYtC/jvp8c9ss6ir81Xw HhQzFQwDPF3iKHjKevOp3dx/wk48FnxZehIDxKPcU58AvEgjO/o6Rc2745SqvXBePd7K3VKKD4g AIgl0AI2VCxEhxXKIVHj2hU4rfcQp+Iw+rcuu8z2j3F0khEJDUE2EtLwKJPktmH3Y4j/b7Mp8vb Wfn+5tAgVTKTE84b5hwXDKSlYaiI8o7uUhaOCL8FP3h1t8mZ4LaUYMpi+ZBDA== X-Received: by 2002:a05:6a20:c90c:b0:3c3:812a:2198 with SMTP id adf61e73a8af0-3cd00e039fcmr12251148637.4.1787158770503; Wed, 19 Aug 2026 09:59:30 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:8d7e:6716:d5db:2855]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327bec30f49sm7687491eec.0.2026.08.19.09.59.29 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 19 Aug 2026 09:59:29 -0700 (PDT) From: Artem Dinaburg To: stable@vger.kernel.org Cc: Xiang Mei , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, Artem Dinaburg Subject: [PATCH 6.1.y] net: bonding: fix use-after-free in bond_xmit_broadcast() Date: Wed, 19 Aug 2026 12:59:22 -0400 Message-ID: <20260819165924.1184-1-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Xiang Mei Please queue the attached backport of upstream commit 2884bf72fb8f. It fixes CVE-2026-31419 in 6.1.y. An unprivileged user can create a broadcast bond and dummy slaves in a user and network namespace. Racing ordinary packet sends with slave release makes `bond_xmit_broadcast()` give the same skb to two transmitters. I reproduced a KASAN use-after-free in `skb_clone()` on v6.1.182. The attached one-line upstream fix applies cleanly to v6.1.182. The same workload completed over one million sends and 299 slave mutations with the patched module and no sanitizer, oops, lock, or BUG output. The fix is already released in 6.6.143, 6.12.95, 6.18.22, and 6.19.12, but no corresponding fix is present in 6.1.y. Signed-off-by: Artem Dinaburg --- drivers/net/bonding/bond_main.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c index 9898d85075d150..4370ba922b2cc2 100644 --- a/drivers/net/bonding/bond_main.c +++ b/drivers/net/bonding/bond_main.c @@ -5344,7 +5344,7 @@ static netdev_tx_t bond_xmit_broadcast(struct sk_buff *skb, if (!(bond_slave_is_up(slave) && slave->link == BOND_LINK_UP)) continue; - if (bond_is_last_slave(bond, slave)) { + if (i + 1 == slaves_count) { skb2 = skb; skb_used = true; } else { -- 2.39.5