mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks
@ 2026-10-01  1:05 Daehyeon Ko
  2026-10-01 17:05 ` Ido Schimmel
  0 siblings, 1 reply; 2+ messages in thread
From: Daehyeon Ko @ 2026-10-01  1:05 UTC (permalink / raw)
  To: David Ahern, Ido Schimmel
  Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, Vladimir Vdovin, netdev, linux-kernel, Daehyeon Ko

Commit 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if
multipath enabled") made __ip_rt_update_pmtu() update every path.

For nexthop objects, fib_info_num_path() and fib_info_nhc()
independently load nh->nh_grp.  RCU protects each group's lifetime but
does not make the loads observe the same group.  If replacement shrinks
the group after the loop accepts an index, fib_info_nhc() returns NULL
and update_or_create_fnhe() dereferences it.

A deterministic probe only widened the existing window between the real
operations.  On v7.2, an RTM_NEWNEXTHOP replacement published a
one-member group after the PMTU reader accepted index 1 from a two-member
group, producing:

  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
  RIP: update_or_create_fnhe+0x45/0x15b0

Stop when the indexed path is absent.  Groups are dense, so no later
index exists in that snapshot.  The same real-writer window completed
114,423 PMTU iterations without an oops with this check.  A reproducer
is available on request.

Replacement requires CAP_NET_ADMIN in the network namespace.  Where
unprivileged user namespaces are permitted, a local user can obtain it
in a new user and network namespace.

Fixes: 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if multipath enabled")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
 net/ipv4/route.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 37674d76f90f0..5f2197874bebc 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -1082,6 +1082,8 @@ static void __ip_rt_update_pmtu(struct rtable *rt, struct flowi4 *fl4, u32 mtu)
 
 			for (nhsel = 0; nhsel < fib_info_num_path(res.fi); nhsel++) {
 				nhc = fib_info_nhc(res.fi, nhsel);
+				if (!nhc)
+					break;
 				update_or_create_fnhe(nhc, fl4->daddr, 0, mtu, lock,
 						      jiffies + net->ipv4.ip_rt_mtu_expires);
 			}

base-commit: 4f1da630d13de0370e2f6361f961f1c8b384af1c
-- 
2.55.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks
  2026-10-01  1:05 [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks Daehyeon Ko
@ 2026-10-01 17:05 ` Ido Schimmel
  0 siblings, 0 replies; 2+ messages in thread
From: Ido Schimmel @ 2026-10-01 17:05 UTC (permalink / raw)
  To: Daehyeon Ko
  Cc: David Ahern, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Vladimir Vdovin, netdev, linux-kernel

On Thu, Oct 01, 2026 at 10:05:50AM +0900, Daehyeon Ko wrote:
> Commit 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if
> multipath enabled") made __ip_rt_update_pmtu() update every path.
> 
> For nexthop objects, fib_info_num_path() and fib_info_nhc()
> independently load nh->nh_grp.  RCU protects each group's lifetime but
> does not make the loads observe the same group.  If replacement shrinks
> the group after the loop accepts an index, fib_info_nhc() returns NULL
> and update_or_create_fnhe() dereferences it.
> 
> A deterministic probe only widened the existing window between the real
> operations.  On v7.2, an RTM_NEWNEXTHOP replacement published a
> one-member group after the PMTU reader accepted index 1 from a two-member
> group, producing:
> 
>   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
>   RIP: update_or_create_fnhe+0x45/0x15b0
> 
> Stop when the indexed path is absent.  Groups are dense, so no later
> index exists in that snapshot.  The same real-writer window completed
> 114,423 PMTU iterations without an oops with this check.  A reproducer
> is available on request.
> 
> Replacement requires CAP_NET_ADMIN in the network namespace.  Where
> unprivileged user namespaces are permitted, a local user can obtain it
> in a new user and network namespace.
> 
> Fixes: 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if multipath enabled")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>

Reviewed-by: Ido Schimmel <idosch@nvidia.com>

Please check fib_dump_info_fnhe(). It seems to suffer from the same
problem since commit 4ce5dc9316de ("inet: switch inet_dump_fib() to RCU
protection").

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-01 17:06 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01  1:05 [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks Daehyeon Ko
2026-10-01 17:05 ` Ido Schimmel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®