mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Omar Ramadan <omar@blockcast.net>
To: Taehee Yoo <ap420073@gmail.com>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@kernel.org>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	Simon Horman <horms@kernel.org>
Subject: [PATCH net v2 0/3] amt: fix relay tunnel keying and unauthenticated-Request DoS
Date: Fri,  9 Oct 2026 20:14:51 +0000	[thread overview]
Message-ID: <20261009201455.1904698-1-omar@blockcast.net> (raw)

This series fixes related problems in the AMT relay in
drivers/net/amt.c. The relay creates and mutates per-tunnel state in
response to AMT Request messages whose source is never validated, so a
spoofed-source flood exhausts the tunnel table and reflects Membership
Queries at arbitrary addresses. The same code keys tunnels on the source
address alone, so two gateways behind one NAT collide.

Reported privately to security@kernel.org first. The security team
determined there is no memory-safety exposure and no embargo is needed,
and asked that the fix be posted here in the open with Taehee Yoo in Cc.

Patches 1 and 3 carry Fixes: cbc21dc1cfe9. Patch 3 is the core fix: the
relay now answers a Request statelessly (it computes the response MAC
and emits the Query without allocating a tunnel) and only commits tunnel
state once the gateway echoes the nonce+MAC in an Update. A spoofed
source cannot complete that exchange, so it allocates nothing.

Testing: booted net at commit 6d25ffca055a ("cipso: adjust cached
option offsets when removing CIPSO") plus this series (arm64, QEMU via
virtme-ng) with CONFIG_KASAN=y, CONFIG_PROVE_LOCKING=y,
CONFIG_PROVE_RCU=y and CONFIG_DEBUG_LIST=y on top of
tools/testing/selftests/net/config. amt.sh passes all six tests,
including both forwarding-torture cases, with no KASAN, lockdep or RCU
reports, and debug_locks stays 1. Every case completes a real gateway
handshake, so this exercises the stateless Request path and the MAC
check on Update. drivers/net/amt.c and include/net/amt.h are unchanged
between that commit and the base-commit below.

A companion change bounds the number of verified tunnels admitted per
source address. It adds a new netlink attribute and so targets net-next
as a separate posting, not part of this series. One note on its default:
a per-source cap closes the non-spoofing exhaustion path (one host, many
real handshakes) that this series does not, but a low fixed default is
wrong behind carrier-grade NAT, where many independent subscribers share
one public address and would be refused past the cap. The net-next
posting sets the default accordingly and documents the CGNAT case; this
series does not depend on that cap and closes the spoofing primitive on
its own.

Changes in v2:
- Drop v1 patch 2/4 ("amt: send the relay General Query directly
  instead of via dev_queue_xmit"). The same fix is already in net as
  commit afae89de73dd ("amt: send the relay's General Query directly
  from the receive path"). v1 was generated against v7.1 and did not
  apply to net.
- Rebase onto net. In patch 1, the port check uses the header fields
  that amt_update_handler() now snapshots before the pull. In patch 3,
  the Query senders keep that commit's tx_dropped accounting and take
  the destination by value.
- Redo the testing on net. The forwarding-torture subtests now run to
  completion.
v1: https://lore.kernel.org/netdev/20261008003606.3666617-1-omar@blockcast.net/

Omar Ramadan (3):
  amt: key relay tunnel state on the (address, port) endpoint, not the
    address
  amt: make pre-query report drops visible
  amt: do not create tunnel state for unauthenticated Requests

 drivers/net/amt.c | 266 +++++++++++++++++++++++++++++++---------------
 include/net/amt.h |  11 +-
 2 files changed, 185 insertions(+), 92 deletions(-)


base-commit: 37f12441f557468a56c1e27790413aa78c82afa2
-- 
2.47.3


             reply	other threads:[~2026-10-09 20:14 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 20:14 Omar Ramadan [this message]
2026-10-09 20:14 ` [PATCH net v2 1/3] amt: key relay tunnel state on the (address, port) endpoint, not the address Omar Ramadan
2026-10-09 20:14 ` [PATCH net v2 2/3] amt: make pre-query report drops visible Omar Ramadan
2026-10-09 20:14 ` [PATCH net v2 3/3] amt: do not create tunnel state for unauthenticated Requests Omar Ramadan
2026-10-09 20:19 ` [PATCH net v2 0/3] amt: fix relay tunnel keying and unauthenticated-Request DoS netdev-bot+sinfo
2026-10-09 21:37 ` Omar Ramadan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261009201455.1904698-1-omar@blockcast.net \
    --to=omar@blockcast.net \
    --cc=andrew+netdev@lunn.ch \
    --cc=ap420073@gmail.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®