mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups
@ 2026-10-10  7:25 Henry Martin
  2026-10-10  7:29 ` netdev-bot+sinfo
  2026-10-10  8:26 ` Eric Dumazet
  0 siblings, 2 replies; 4+ messages in thread
From: Henry Martin @ 2026-10-10  7:25 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Eric Dumazet, Paolo Abeni,
	Simon Horman, Nicolas Dichtel, Kees Cook, Ilya Maximets,
	Breno Leitao, Jeff Layton, Kexin Sun
  Cc: netdev, linux-kernel, Henry Martin, stable

netlink_realloc_groups() sizes nlk->groups to the number of groups
that exist at bind/ADD_MEMBERSHIP time.  When more multicast groups
are registered later (e.g. a new genl family), existing sockets keep
their smaller bitmap.

__netlink_clear_multicast_users() however iterates every group of
the departing family and calls netlink_update_socket_mc() for each
socket on mc_list, which does test_bit()/__assign_bit() on group - 1
with no regard to nlk->ngroups.  A stale socket therefore gets bits
read and cleared past its bitmap allocation, corrupting whichever
heap object follows it; the corruption repeats on every family
unregister.

Skip groups that lie beyond the socket's bitmap: such a socket could
never have joined them.

This issue was discovered by Tencent CodeBuddy Security.

Cc: stable@vger.kernel.org
Fixes: b4ff4f0419ae ("[NETLINK]: allocate group bitmaps dynamically")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
---
 net/netlink/af_netlink.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 9fdf964224ab4..8cc655aa927f1 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -1657,6 +1657,12 @@ static void netlink_update_socket_mc(struct netlink_sock *nlk,
 {
 	int old, new = !!is_new, subscriptions;
 
+	/* A socket whose bitmap predates this group can never be a member;
+	 * don't touch bits beyond its allocation.
+	 */
+	if (group - 1 >= nlk->ngroups)
+		return;
+
 	old = test_bit(group - 1, nlk->groups);
 	subscriptions = nlk->subscriptions - old + new;
 	__assign_bit(group - 1, nlk->groups, new);
-- 
2.43.7


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-10  8:42 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10  7:25 [PATCH net] netlink: fix out-of-bounds bitmap access clearing stale mc groups Henry Martin
2026-10-10  7:29 ` netdev-bot+sinfo
2026-10-10  8:26 ` Eric Dumazet
2026-10-10  8:42   ` henry martin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®