* [PATCH net] netlink: avoid hashing the network namespace pointer
@ 2026-10-06 22:41 Kyle Zeng
2026-10-06 22:49 ` netdev-bot+sinfo
2026-10-07 5:42 ` Eric Dumazet
0 siblings, 2 replies; 4+ messages in thread
From: Kyle Zeng @ 2026-10-06 22:41 UTC (permalink / raw)
To: netdev
Cc: linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures,
Kyle Zeng
The netlink rhashtable key includes a raw struct net pointer and a
user-controlled port ID. Both /proc/net/netlink and socket diagnostics
expose the table's bucket order. By binding and rebinding chosen
NETLINK_USERSOCK port IDs, an unprivileged reader can distinguish equal
buckets and recover the low bits of the Jenkins hash. Its 32-bit seed
and the limited set of kernel-image slides can then be searched offline
to recover the address of init_net.
Use the namespace's unique, non-address ID in the comparison key
instead. This ID is assigned before the per-net initializers run and
remains unchanged for the namespace's lifetime. The lookup key and
object hash are still built by netlink_compare_arg_init(), keeping
lookup, insertion, removal and rehashing consistent while preserving
namespace separation. Neither public table walker needs to change.
Fixes: c428ecd1a21f ("netlink: Move namespace into hash key")
Assisted-by: Codex:gpt-6-astra
Signed-off-by: Kyle Zeng <kylebot@openai.com>
---
net/netlink/af_netlink.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 9fdf964224ab..e62bb67b78b0 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -464,7 +464,7 @@ netlink_unlock_table(void)
struct netlink_compare_arg
{
- possible_net_t pnet;
+ u64 netns_id;
u32 portid;
};
@@ -479,14 +479,14 @@ static inline int netlink_compare(struct rhashtable_compare_arg *arg,
const struct netlink_sock *nlk = ptr;
return nlk->portid != x->portid ||
- !net_eq(sock_net(&nlk->sk), read_pnet(&x->pnet));
+ sock_net(&nlk->sk)->ns.ns_id != x->netns_id;
}
static void netlink_compare_arg_init(struct netlink_compare_arg *arg,
struct net *net, u32 portid)
{
memset(arg, 0, sizeof(*arg));
- write_pnet(&arg->pnet, net);
+ arg->netns_id = net->ns.ns_id;
arg->portid = portid;
}
base-commit: fd179f8a05be3ccae366b9b96e176b51fbe54aab
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: avoid hashing the network namespace pointer
2026-10-06 22:41 [PATCH net] netlink: avoid hashing the network namespace pointer Kyle Zeng
@ 2026-10-06 22:49 ` netdev-bot+sinfo
2026-10-07 5:24 ` Kyle Zeng
2026-10-07 5:42 ` Eric Dumazet
1 sibling, 1 reply; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-10-06 22:49 UTC (permalink / raw)
To: Kyle Zeng
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: avoid hashing the network namespace pointer
2026-10-06 22:49 ` netdev-bot+sinfo
@ 2026-10-07 5:24 ` Kyle Zeng
0 siblings, 0 replies; 4+ messages in thread
From: Kyle Zeng @ 2026-10-07 5:24 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
On Tue, Oct 06, 2026 at 10:49:20PM +0000, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
I have a PoC for this issue and the symptom is that it can lead to
information leak (kernel text pointer).
Best,
Kyle
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: avoid hashing the network namespace pointer
2026-10-06 22:41 [PATCH net] netlink: avoid hashing the network namespace pointer Kyle Zeng
2026-10-06 22:49 ` netdev-bot+sinfo
@ 2026-10-07 5:42 ` Eric Dumazet
1 sibling, 0 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-10-07 5:42 UTC (permalink / raw)
To: Kyle Zeng, netdev; +Cc: linux-kernel, davem, kuba, pabeni, outbounddisclosures
On 10/7/26 00:41, Kyle Zeng wrote:
> The netlink rhashtable key includes a raw struct net pointer and a
> user-controlled port ID. Both /proc/net/netlink and socket diagnostics
> expose the table's bucket order. By binding and rebinding chosen
> NETLINK_USERSOCK port IDs, an unprivileged reader can distinguish equal
> buckets and recover the low bits of the Jenkins hash. Its 32-bit seed
> and the limited set of kernel-image slides can then be searched offline
> to recover the address of init_net.
>
> Use the namespace's unique, non-address ID in the comparison key
> instead. This ID is assigned before the per-net initializers run and
> remains unchanged for the namespace's lifetime. The lookup key and
> object hash are still built by netlink_compare_arg_init(), keeping
> lookup, insertion, removal and rehashing consistent while preserving
> namespace separation. Neither public table walker needs to change.
>
Please use net->net_cookie instead.
It has the same value in current trees (net->net_cookie =
ns_tree_gen_id(net)),
but ns.ns_id only appeared in 6.18, while your Fixes: tag points to
a 2015 commit.
net_cookie is set at the top of setup_net() in stable kernels >= 5.15,
so backports would be trivial.
> struct netlink_compare_arg
> {
> - possible_net_t pnet;
> + u64 netns_id;
'netns_id' is confusing, we already have NETNSA_NSID and net->netns_ids.
> - !net_eq(sock_net(&nlk->sk), read_pnet(&x->pnet));
> + sock_net(&nlk->sk)->ns.ns_id != x->netns_id;
We now dereference sock_net() from netlink_compare(), under RCU,
possibly for a socket of a dismantling netns.
I think this is fine (sockets are freed after call_rcu(), and
cleanup_net() has an rcu_barrier() before freeing the netns),
but please mention it in the changelog.
Thanks.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-07 5:42 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 22:41 [PATCH net] netlink: avoid hashing the network namespace pointer Kyle Zeng
2026-10-06 22:49 ` netdev-bot+sinfo
2026-10-07 5:24 ` Kyle Zeng
2026-10-07 5:42 ` Eric Dumazet
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®