From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f169.google.com (mail-yw1-f169.google.com [209.85.128.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87F333A7F70 for ; Tue, 25 Aug 2026 05:24:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787635452; cv=none; b=XYj7KiSzsR4mfmNBvFqiEUTWltk/xd6o9CxtNda8p7CivlX1WVjP85i9ZgWMxx6qYiph3MC5ObLj4ROr2mKP4R9/u7iHB8eaQo+B8mImIu55QvZ7HQw3xYmNQnpCL6qTJW3kW55uXUTnEsYCz/HwnRXQ6fZmBtl8IGXE0R3B1+M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787635452; c=relaxed/simple; bh=Cnm0NvLDpK5WEjqJZeD0ehir/4mK4rZsV7l3bVzQ9B8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eD9RGYGyB4qq2eInbJnRGzRxW0GWwXoDwpEAaik0D/9sx2Fv3u34w2D1nwOJb/NLGq9moMYJG4hExaEtR+EhCgkOuMV4NyBoWNnzxQXxCGSeuY4kW8BwYgYc7TajLWBLfkB3xnDoJCw9MvgdeUmJyViQCGAk+M4qcrNI433hVS8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cwXLSHJ0; arc=none smtp.client-ip=209.85.128.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cwXLSHJ0" Received: by mail-yw1-f169.google.com with SMTP id 00721157ae682-855a66e5b5dso1347127b3.0 for ; Mon, 24 Aug 2026 22:24:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787635449; x=1788240249; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/5Oa7EYj+aGHCCFiWFn1S8ybUNVYzm4EISFL7x7oRPk=; b=cwXLSHJ0efW4KQF1jeDDBzznneKFGkSkptYat4lriUwoSgYG1P9KUnDHOx5s56mKLj LqeDLWWZiv49D1BgRuxQJKme1oHCJFU/aahOKSy5G5WW1a7u5CJM0+vLXons54zEiDIH 5sDlMmcklty0XeB8QXLXQh9xBalQzK7Rt3suVUHpXELxMAf7YsWah8uITih+jchvmWLs MPSMH841VqI654xL/QFJWPOc3vUPwh7xpXkWClPrZnX/Kvf5bufZ7T2jKJ2GKxxQylsL U73lfix5pxMOzC4ETU3RZldM46bHbh/udoziCi7TK2mqwRN+P17ygwk2Xv6bAjzBGWHf 2gNw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787635449; x=1788240249; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/5Oa7EYj+aGHCCFiWFn1S8ybUNVYzm4EISFL7x7oRPk=; b=W9d/IY7P69LZy5a0NIMeLTx6WfL3a9d9+/Nrd1ZB8zmPnsI0C9I/gm2EX+zj/78JSd uorTG97bLNHBNsCTuqOYEf5nVRHm1dsMfwv9BSmnlq0IvdCU56LW4vrLg+dYvPV77Z8P UjM873qd67qvnkQeGJJCvbF6Kg3yZ225qiqpv+DeCZq2hCL4dUvkPDRg0AXkcorxowEr ULeTVPBV6XRLs8hJnT2b7k0cWSoTYtxOUXWgjk/0Fs9NyfAchL0+2W11/EYkvq5CHMYk ofn1A9uadegqOejFh6qwMghktMqIxNxE5pUJdElsphPMU5Vsxyywml4eMSduy+O5DxvC /Qkg== X-Forwarded-Encrypted: i=1; AHgh+Ro12cCRX8/SY6H5WnKxR/O69HRGD0sbfS9Ds+tP+lTSxZ4uUMdRZVR+cty5NIEYyJN5S69g15QLYrDidqo=@vger.kernel.org X-Gm-Message-State: AFuF++n8mgg/9hlJyRFkdZYN2OAbwNdeUZ+PPft24n0MZGd3oONPbgMY Exe9sH0hl/U/ok3TzGS8udMp6ieRIWB2WGRZBOU9rAYJydaqDSHVUA3W X-Gm-Gg: AR+sD11064cF0Di4Wwd5cRHMTuvVlMzKxwEqKh3LvpSe6jEBwW3WbjcI+KEgQa5oLCH NOlhgctDRdkn269gCz6KtyiwfYB8QlRL0mxubIM4o0ds6u+alCCMxzmn01KLsRO+vNhSrEkvJQ9 sCNL80+Yr3GI0O46pFM6/cwryAY6Jig3rOKgTHTkFPmh/dWcKHBRRtqfpSf5HSIpKjd6WW90wum s+aMiNS+DAqpxUhlnpMcX/8Gm5y58IGZ56IWm33hy+ArJz90byiI6lmgshLevfESp6pEtIpBZuQ sUWKemFC3yqKx0oDNWcfyjDRXVk5j6zp8mL0EJyKFkzc3im2ZMVYiFSHsKRQynRgFQpQ/3E4AuZ 60bV2PWnjgbLEEvpSl/dhgP+4pSzZvL22g53ZUZ3MwgpBhsepdnN2Ij+QiWUC6aUwoLRBUbz+h9 Gdj2NzL3So7cInETrGoAS2+7sxuJQFRCFWoEaEFH4xeyt/JL8R07/jJa5iH85FlWcLvDA= X-Received: by 2002:a05:690c:c15:b0:81d:75b4:925f with SMTP id 00721157ae682-849f4c6ffd3mr130520957b3.19.1787635449512; Mon, 24 Aug 2026 22:24:09 -0700 (PDT) Received: from mac.lan ([136.55.173.105]) by smtp.gmail.com with ESMTPSA id 00721157ae682-851e1419e0bsm21767747b3.26.2026.08.24.22.24.08 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 24 Aug 2026 22:24:08 -0700 (PDT) From: "Cen Zhang (Microsoft)" To: pablo@netfilter.org, laforge@gnumonks.org, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: horms@kernel.org, anthony.l.nguyen@intel.com, wojciech.drewek@intel.com, osmocom-net-gprs@lists.osmocom.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, AutonomousCodeSecurity@microsoft.com, xmei5@asu.edu, tgopinath@linux.microsoft.com, kys@microsoft.com, blbllhy@gmail.com Subject: [PATCH net v2 1/2] gtp: fix sk_created publication race in gtp_create_sockets() Date: Tue, 25 Aug 2026 01:24:03 -0400 Message-ID: <20260825052404.45665-2-blbllhy@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260825052404.45665-1-blbllhy@gmail.com> References: <20260825052404.45665-1-blbllhy@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit In gtp_create_sockets(), gtp->sk_created is set to true before gtp->sk0 and gtp->sk1u are assigned. Without memory ordering guarantees, a concurrent GTP Echo packet on another CPU can observe sk_created == true while gtp->sk0 is still NULL, causing a kernel panic. KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:gtp_encap_recv (drivers/net/gtp.c:542 gtp0_handle_echo_resp) Call Trace: udp_queue_rcv_one_skb ip_protocol_deliver_rcu ip_local_deliver Kernel panic - not syncing: Fatal exception in interrupt Use smp_store_release() when publishing sk_created and smp_load_acquire() on every lockless read. This ensures that all prior stores (sk0, sk1u assignments) are visible before any reader can observe the flag as true, on all architectures. Annotate all remaining lockless sk_created accesses with smp_store_release()/smp_load_acquire(). Suggested-by: Simon Horman Fixes: b20dc3c68458 ("gtp: Allow to create GTP device without FDs") Reported-by: AutonomousCodeSecurity@microsoft.com Reported-by: Xiang Mei (Microsoft) Reported-by: Cen Zhang (Microsoft) Signed-off-by: Cen Zhang (Microsoft) --- v2: Use smp_store_release()/smp_load_acquire() to provide proper memory ordering as suggested by Simon Horman. v1: https://lore.kernel.org/netdev/20260816035205.57966-1-blbllhy@gmail.com/ --- drivers/net/gtp.c | 29 ++++++++++++++++++++++------- 1 file changed, 22 insertions(+), 7 deletions(-) diff --git a/drivers/net/gtp.c b/drivers/net/gtp.c index 298efc76a56b..ead519ee18d1 100644 --- a/drivers/net/gtp.c +++ b/drivers/net/gtp.c @@ -603,10 +603,12 @@ static int gtp0_udp_encap_recv(struct gtp_dev *gtp, struct sk_buff *skb) * there is no daemon running in userspace which would * handle echo request. */ - if (gtp0->type == GTP_ECHO_REQ && gtp->sk_created) + /* Pairs with smp_store_release() in gtp_create_sockets(). */ + if (gtp0->type == GTP_ECHO_REQ && smp_load_acquire(>p->sk_created)) return gtp0_send_echo_resp(gtp, skb); - if (gtp0->type == GTP_ECHO_RSP && gtp->sk_created) + /* Pairs with smp_store_release() in gtp_create_sockets(). */ + if (gtp0->type == GTP_ECHO_RSP && smp_load_acquire(>p->sk_created)) return gtp0_handle_echo_resp(gtp, skb); if (gtp0->type != GTP_TPDU) @@ -811,10 +813,12 @@ static int gtp1u_udp_encap_recv(struct gtp_dev *gtp, struct sk_buff *skb) * there is no daemon running in userspace which would * handle echo request. */ - if (gtp1->type == GTP_ECHO_REQ && gtp->sk_created) + /* Pairs with smp_store_release() in gtp_create_sockets(). */ + if (gtp1->type == GTP_ECHO_REQ && smp_load_acquire(>p->sk_created)) return gtp1u_send_echo_resp(gtp, skb); - if (gtp1->type == GTP_ECHO_RSP && gtp->sk_created) + /* Pairs with smp_store_release() in gtp_create_sockets(). */ + if (gtp1->type == GTP_ECHO_RSP && smp_load_acquire(>p->sk_created)) return gtp1u_handle_echo_resp(gtp, skb); if (gtp1->type != GTP_TPDU) @@ -894,7 +898,10 @@ static void gtp_encap_disable(struct gtp_dev *gtp) if (gtp->sk_created) { udp_tunnel_sock_release(gtp->sk0); udp_tunnel_sock_release(gtp->sk1u); - gtp->sk_created = false; + /* Pairs with smp_load_acquire() in the RX and + * genl echo paths. + */ + smp_store_release(>p->sk_created, false); gtp->sk0 = NULL; gtp->sk1u = NULL; } else { @@ -1462,10 +1469,15 @@ static int gtp_create_sockets(struct gtp_dev *gtp, const struct nlattr *nla, return PTR_ERR(sk1u); } - gtp->sk_created = true; gtp->sk0 = sk0; gtp->sk1u = sk1u; + /* Ensure sk0/sk1u are visible before sk_created is set. + * Pairs with smp_load_acquire() in the RX and genl + * echo paths. + */ + smp_store_release(>p->sk_created, true); + return 0; } @@ -2365,7 +2377,10 @@ static int gtp_genl_send_echo_req(struct sk_buff *skb, struct genl_info *info) if (!gtp) return -ENODEV; - if (!gtp->sk_created) + /* Pairs with smp_store_release() in gtp_create_sockets() + * and gtp_encap_disable(). + */ + if (!smp_load_acquire(>p->sk_created)) return -EOPNOTSUPP; if (!(gtp->dev->flags & IFF_UP)) return -ENETDOWN; -- 2.55.0