From: Omar Ramadan <omar@blockcast.net>
To: Taehee Yoo <ap420073@gmail.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
Simon Horman <horms@kernel.org>
Subject: [PATCH net 0/4] amt: fix relay tunnel keying and unauthenticated-Request DoS
Date: Thu, 8 Oct 2026 00:36:01 +0000 [thread overview]
Message-ID: <20261008003606.3666617-1-omar@blockcast.net> (raw)
This series fixes four related problems in the AMT relay data path in
drivers/net/amt.c. The relay creates and mutates per-tunnel state in
response to AMT Request messages whose source is never validated, so a
spoofed-source flood exhausts the tunnel table and reflects Membership
Queries at arbitrary addresses. The same code keys tunnels on the source
address alone, so two gateways behind one NAT collide, and it drops
several packet classes with no counter.
Reported privately to security@kernel.org first. The security team
determined there is no memory-safety exposure and no embargo is needed,
and asked that the fix be posted here in the open with Taehee Yoo in Cc.
1 amt: key relay tunnel state on the (address, port) endpoint
2 amt: send the relay General Query directly instead of via
dev_queue_xmit
3 amt: make pre-query report drops visible
4 amt: do not create tunnel state for unauthenticated Requests
Patches 1, 2 and 4 carry Fixes: cbc21dc1cfe9 and target net. Patch 4 is
the core fix: the relay now answers a Request statelessly (it computes
the response MAC and emits the Query without allocating a tunnel) and
only commits tunnel state once the gateway echoes the nonce+MAC in an
Update. A spoofed source cannot complete that exchange, so it allocates
nothing.
Testing: applied to net (v7.1, 8cd9520d35a6) and booted with
CONFIG_KASAN=y and CONFIG_PROVE_LOCKING=y. tools/testing/selftests/net/
amt.sh was run against the booted kernel: the discovery and IPv4/IPv6
multicast-forwarding tests pass, with no KASAN or lockdep reports across
tunnel setup, the gateway handshake, and data forwarding. (The IPv4
throughput-torture subtest streams ~1 GB of /dev/urandom per family and
is bound by the sanitizer-slowed test VM; it was still making forward
progress at the time limit with no splats.)
A companion change bounds the number of verified tunnels admitted per
source address. It adds a new netlink attribute and so targets net-next
as a separate posting, not part of this series. One note on its default:
a per-source cap closes the non-spoofing exhaustion path (one host, many
real handshakes) that this series does not, but a low fixed default is
wrong behind carrier-grade NAT, where many independent subscribers share
one public address and would be refused past the cap. The net-next
posting sets the default accordingly and documents the CGNAT case; this
series does not depend on that cap and closes the spoofing primitive on
its own.
base: applies to net, commit 8cd9520d35a6 ("Linux 7.1").
Omar Ramadan (4):
amt: key relay tunnel state on the (address, port) endpoint, not the
address
amt: send the relay General Query directly instead of via
dev_queue_xmit
amt: make pre-query report drops visible
amt: do not create tunnel state for unauthenticated Requests
drivers/net/amt.c | 315 +++++++++++++++++++++++++++++-----------------
include/net/amt.h | 15 +--
2 files changed, 206 insertions(+), 124 deletions(-)
--
2.43.0
next reply other threads:[~2026-10-08 0:36 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 0:36 Omar Ramadan [this message]
2026-10-08 0:36 ` [PATCH net 1/4] amt: key relay tunnel state on the (address, port) endpoint, not the address Omar Ramadan
2026-10-08 0:36 ` [PATCH net 2/4] amt: send the relay General Query directly instead of via dev_queue_xmit Omar Ramadan
2026-10-08 0:36 ` [PATCH net 3/4] amt: make pre-query report drops visible Omar Ramadan
2026-10-08 0:36 ` [PATCH net 4/4] amt: do not create tunnel state for unauthenticated Requests Omar Ramadan
2026-10-08 0:39 ` [PATCH net 0/4] amt: fix relay tunnel keying and unauthenticated-Request DoS netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008003606.3666617-1-omar@blockcast.net \
--to=omar@blockcast.net \
--cc=andrew+netdev@lunn.ch \
--cc=ap420073@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®