* [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups
@ 2026-10-10 7:25 Henry Martin
2026-10-10 7:29 ` netdev-bot+sinfo
2026-10-10 8:26 ` Eric Dumazet
0 siblings, 2 replies; 4+ messages in thread
From: Henry Martin @ 2026-10-10 7:25 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Eric Dumazet, Paolo Abeni,
Simon Horman, Nicolas Dichtel, Kees Cook, Ilya Maximets,
Breno Leitao, Jeff Layton, Kexin Sun
Cc: netdev, linux-kernel, Henry Martin, stable
netlink_realloc_groups() sizes nlk->groups to the number of groups
that exist at bind/ADD_MEMBERSHIP time. When more multicast groups
are registered later (e.g. a new genl family), existing sockets keep
their smaller bitmap.
__netlink_clear_multicast_users() however iterates every group of
the departing family and calls netlink_update_socket_mc() for each
socket on mc_list, which does test_bit()/__assign_bit() on group - 1
with no regard to nlk->ngroups. A stale socket therefore gets bits
read and cleared past its bitmap allocation, corrupting whichever
heap object follows it; the corruption repeats on every family
unregister.
Skip groups that lie beyond the socket's bitmap: such a socket could
never have joined them.
This issue was discovered by Tencent CodeBuddy Security.
Cc: stable@vger.kernel.org
Fixes: b4ff4f0419ae ("[NETLINK]: allocate group bitmaps dynamically")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
---
net/netlink/af_netlink.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 9fdf964224ab4..8cc655aa927f1 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -1657,6 +1657,12 @@ static void netlink_update_socket_mc(struct netlink_sock *nlk,
{
int old, new = !!is_new, subscriptions;
+ /* A socket whose bitmap predates this group can never be a member;
+ * don't touch bits beyond its allocation.
+ */
+ if (group - 1 >= nlk->ngroups)
+ return;
+
old = test_bit(group - 1, nlk->groups);
subscriptions = nlk->subscriptions - old + new;
__assign_bit(group - 1, nlk->groups, new);
--
2.43.7
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups
2026-10-10 7:25 [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups Henry Martin
@ 2026-10-10 7:29 ` netdev-bot+sinfo
2026-10-10 8:26 ` Eric Dumazet
1 sibling, 0 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-10-10 7:29 UTC (permalink / raw)
To: Henry Martin
Cc: David S . Miller, Jakub Kicinski, Eric Dumazet, Paolo Abeni,
Simon Horman, Nicolas Dichtel, Kees Cook, Ilya Maximets,
Breno Leitao, Jeff Layton, Kexin Sun, netdev, linux-kernel,
stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups
2026-10-10 7:25 [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups Henry Martin
2026-10-10 7:29 ` netdev-bot+sinfo
@ 2026-10-10 8:26 ` Eric Dumazet
2026-10-10 8:42 ` henry martin
1 sibling, 1 reply; 4+ messages in thread
From: Eric Dumazet @ 2026-10-10 8:26 UTC (permalink / raw)
To: Henry Martin
Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
Nicolas Dichtel, Kees Cook, Ilya Maximets, Breno Leitao,
Jeff Layton, Kexin Sun, netdev, linux-kernel, stable
Le sam. 10 oct. 2026 à 09:26, Henry Martin <bsdhenrymartin@gmail.com> a écrit :
>
> netlink_realloc_groups() sizes nlk->groups to the number of groups
> that exist at bind/ADD_MEMBERSHIP time. When more multicast groups
> are registered later (e.g. a new genl family), existing sockets keep
> their smaller bitmap.
>
> __netlink_clear_multicast_users() however iterates every group of
> the departing family and calls netlink_update_socket_mc() for each
> socket on mc_list, which does test_bit()/__assign_bit() on group - 1
> with no regard to nlk->ngroups. A stale socket therefore gets bits
> read and cleared past its bitmap allocation, corrupting whichever
> heap object follows it; the corruption repeats on every family
> unregister.
Do you have a KASAN report, or is this from static analysis only ?
nl_table[NETLINK_GENERIC].groups only grows when group ids no longer
fit in mc_groups_longs * BITS_PER_LONG.
On 64bit, 59 ids are free in the initial bitmap. I count 58 genl
multicast groups in the whole tree, 4 of them using reserved ids
(ctrl, quota, pmcraid, NET_DM), so 54 dynamically allocated ones
if every family was loaded at the same time.
I do not see how a 64bit kernel with in-tree families can get there.
32bit kernels could, and then only from genl_unregister_family(),
i.e. at module unload.
The check itself looks fine and matches what do_one_broadcast()
does, but the changelog should describe the real conditions instead
of suggesting a generic heap corruption.
Unless you have a reproducer, I think this is net-next material,
without the Cc: stable.
>
> Skip groups that lie beyond the socket's bitmap: such a socket could
> never have joined them.
>
> This issue was discovered by Tencent CodeBuddy Security.
>
> Cc: stable@vger.kernel.org
> Fixes: b4ff4f0419ae ("[NETLINK]: allocate group bitmaps dynamically")
This commit did not add netlink_update_socket_mc() or
netlink_clear_multicast_users(). This should be
Fixes: 84659eb529b3 ("[NETLIKN]: Allow removing multicast groups.")
> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
> ---
> net/netlink/af_netlink.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
> index 9fdf964224ab4..8cc655aa927f1 100644
> --- a/net/netlink/af_netlink.c
> +++ b/net/netlink/af_netlink.c
> @@ -1657,6 +1657,12 @@ static void netlink_update_socket_mc(struct netlink_sock *nlk,
> {
> int old, new = !!is_new, subscriptions;
>
> + /* A socket whose bitmap predates this group can never be a member;
> + * don't touch bits beyond its allocation.
> + */
> + if (group - 1 >= nlk->ngroups)
> + return;
> +
> old = test_bit(group - 1, nlk->groups);
> subscriptions = nlk->subscriptions - old + new;
> __assign_bit(group - 1, nlk->groups, new);
> --
> 2.43.7
>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups
2026-10-10 8:26 ` Eric Dumazet
@ 2026-10-10 8:42 ` henry martin
0 siblings, 0 replies; 4+ messages in thread
From: henry martin @ 2026-10-10 8:42 UTC (permalink / raw)
To: Eric Dumazet
Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
Nicolas Dichtel, Kees Cook, Ilya Maximets, Breno Leitao,
Jeff Layton, Kexin Sun, netdev, linux-kernel, stable
Hi Eric,
Thanks for the careful review, you're right on all points.
This came from static analysis; I don't have a KASAN report. For
what it's worth, 32-bit x86 cannot provide one either, since
HAVE_ARCH_KASAN there is X86_64-only, and on 64-bit a reproducer
would need an out-of-tree family to push the table past the initial
bitmap.
v2 corrects the Fixes tag to 84659eb529b3, scopes the changelog to
the actual reachability (32-bit kernels with in-tree families, at
module unload) instead of implying generic corruption, and drops
Cc: stable.
Regards,
Henry
Eric Dumazet <edumazet@kernel.org> 于2026年10月10日周六 16:26写道:
>
> Le sam. 10 oct. 2026 à 09:26, Henry Martin <bsdhenrymartin@gmail.com> a écrit :
> >
> > netlink_realloc_groups() sizes nlk->groups to the number of groups
> > that exist at bind/ADD_MEMBERSHIP time. When more multicast groups
> > are registered later (e.g. a new genl family), existing sockets keep
> > their smaller bitmap.
> >
> > __netlink_clear_multicast_users() however iterates every group of
> > the departing family and calls netlink_update_socket_mc() for each
> > socket on mc_list, which does test_bit()/__assign_bit() on group - 1
> > with no regard to nlk->ngroups. A stale socket therefore gets bits
> > read and cleared past its bitmap allocation, corrupting whichever
> > heap object follows it; the corruption repeats on every family
> > unregister.
>
> Do you have a KASAN report, or is this from static analysis only ?
>
> nl_table[NETLINK_GENERIC].groups only grows when group ids no longer
> fit in mc_groups_longs * BITS_PER_LONG.
>
> On 64bit, 59 ids are free in the initial bitmap. I count 58 genl
> multicast groups in the whole tree, 4 of them using reserved ids
> (ctrl, quota, pmcraid, NET_DM), so 54 dynamically allocated ones
> if every family was loaded at the same time.
>
> I do not see how a 64bit kernel with in-tree families can get there.
> 32bit kernels could, and then only from genl_unregister_family(),
> i.e. at module unload.
>
> The check itself looks fine and matches what do_one_broadcast()
> does, but the changelog should describe the real conditions instead
> of suggesting a generic heap corruption.
>
> Unless you have a reproducer, I think this is net-next material,
> without the Cc: stable.
>
> >
> > Skip groups that lie beyond the socket's bitmap: such a socket could
> > never have joined them.
> >
> > This issue was discovered by Tencent CodeBuddy Security.
> >
> > Cc: stable@vger.kernel.org
> > Fixes: b4ff4f0419ae ("[NETLINK]: allocate group bitmaps dynamically")
>
> This commit did not add netlink_update_socket_mc() or
> netlink_clear_multicast_users(). This should be
>
> Fixes: 84659eb529b3 ("[NETLIKN]: Allow removing multicast groups.")
>
> > Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
> > ---
> > net/netlink/af_netlink.c | 6 ++++++
> > 1 file changed, 6 insertions(+)
> >
> > diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
> > index 9fdf964224ab4..8cc655aa927f1 100644
> > --- a/net/netlink/af_netlink.c
> > +++ b/net/netlink/af_netlink.c
> > @@ -1657,6 +1657,12 @@ static void netlink_update_socket_mc(struct netlink_sock *nlk,
> > {
> > int old, new = !!is_new, subscriptions;
> >
> > + /* A socket whose bitmap predates this group can never be a member;
> > + * don't touch bits beyond its allocation.
> > + */
> > + if (group - 1 >= nlk->ngroups)
> > + return;
> > +
> > old = test_bit(group - 1, nlk->groups);
> > subscriptions = nlk->subscriptions - old + new;
> > __assign_bit(group - 1, nlk->groups, new);
> > --
> > 2.43.7
> >
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-10 8:42 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 7:25 [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups Henry Martin
2026-10-10 7:29 ` netdev-bot+sinfo
2026-10-10 8:26 ` Eric Dumazet
2026-10-10 8:42 ` henry martin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®