* [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks
@ 2026-10-01 1:05 Daehyeon Ko
2026-10-01 17:05 ` Ido Schimmel
0 siblings, 1 reply; 2+ messages in thread
From: Daehyeon Ko @ 2026-10-01 1:05 UTC (permalink / raw)
To: David Ahern, Ido Schimmel
Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, Vladimir Vdovin, netdev, linux-kernel, Daehyeon Ko
Commit 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if
multipath enabled") made __ip_rt_update_pmtu() update every path.
For nexthop objects, fib_info_num_path() and fib_info_nhc()
independently load nh->nh_grp. RCU protects each group's lifetime but
does not make the loads observe the same group. If replacement shrinks
the group after the loop accepts an index, fib_info_nhc() returns NULL
and update_or_create_fnhe() dereferences it.
A deterministic probe only widened the existing window between the real
operations. On v7.2, an RTM_NEWNEXTHOP replacement published a
one-member group after the PMTU reader accepted index 1 from a two-member
group, producing:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: update_or_create_fnhe+0x45/0x15b0
Stop when the indexed path is absent. Groups are dense, so no later
index exists in that snapshot. The same real-writer window completed
114,423 PMTU iterations without an oops with this check. A reproducer
is available on request.
Replacement requires CAP_NET_ADMIN in the network namespace. Where
unprivileged user namespaces are permitted, a local user can obtain it
in a new user and network namespace.
Fixes: 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if multipath enabled")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
net/ipv4/route.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 37674d76f90f0..5f2197874bebc 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -1082,6 +1082,8 @@ static void __ip_rt_update_pmtu(struct rtable *rt, struct flowi4 *fl4, u32 mtu)
for (nhsel = 0; nhsel < fib_info_num_path(res.fi); nhsel++) {
nhc = fib_info_nhc(res.fi, nhsel);
+ if (!nhc)
+ break;
update_or_create_fnhe(nhc, fl4->daddr, 0, mtu, lock,
jiffies + net->ipv4.ip_rt_mtu_expires);
}
base-commit: 4f1da630d13de0370e2f6361f961f1c8b384af1c
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks
2026-10-01 1:05 [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks Daehyeon Ko
@ 2026-10-01 17:05 ` Ido Schimmel
0 siblings, 0 replies; 2+ messages in thread
From: Ido Schimmel @ 2026-10-01 17:05 UTC (permalink / raw)
To: Daehyeon Ko
Cc: David Ahern, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Vladimir Vdovin, netdev, linux-kernel
On Thu, Oct 01, 2026 at 10:05:50AM +0900, Daehyeon Ko wrote:
> Commit 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if
> multipath enabled") made __ip_rt_update_pmtu() update every path.
>
> For nexthop objects, fib_info_num_path() and fib_info_nhc()
> independently load nh->nh_grp. RCU protects each group's lifetime but
> does not make the loads observe the same group. If replacement shrinks
> the group after the loop accepts an index, fib_info_nhc() returns NULL
> and update_or_create_fnhe() dereferences it.
>
> A deterministic probe only widened the existing window between the real
> operations. On v7.2, an RTM_NEWNEXTHOP replacement published a
> one-member group after the PMTU reader accepted index 1 from a two-member
> group, producing:
>
> KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
> RIP: update_or_create_fnhe+0x45/0x15b0
>
> Stop when the indexed path is absent. Groups are dense, so no later
> index exists in that snapshot. The same real-writer window completed
> 114,423 PMTU iterations without an oops with this check. A reproducer
> is available on request.
>
> Replacement requires CAP_NET_ADMIN in the network namespace. Where
> unprivileged user namespaces are permitted, a local user can obtain it
> in a new user and network namespace.
>
> Fixes: 7d3f3b4367f3 ("net: ipv4: Cache pmtu for all packet paths if multipath enabled")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Please check fib_dump_info_fnhe(). It seems to suffer from the same
problem since commit 4ce5dc9316de ("inet: switch inet_dump_fib() to RCU
protection").
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-01 17:06 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 1:05 [PATCH net] ipv4: stop PMTU walk when nexthop group shrinks Daehyeon Ko
2026-10-01 17:05 ` Ido Schimmel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®