From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f72.google.com (mail-oo1-f72.google.com [209.85.161.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1459827F4F5 for ; Fri, 14 Aug 2026 02:50:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.72 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786675806; cv=none; b=NGXbRqpAz8NNoYzx29PdFdLfd6G/LJatSvtzvXESJ6g0O8+rfs94bWm3VCon80Unp+bhYO8Xl7jX4d7aNNYypklD2s3m8GGge1EKjK7pUM3kRryRre6eHDyrvM+VGSgoZearueLzmhB06/A1xpfINFPQHWOyH+SORNzT9ByDNWU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786675806; c=relaxed/simple; bh=EpWyEfDr1VXqQ72IZ90fVGNB02b+4ZQzYNFIomJbyRU=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=uGnUWsPCZSCXu2PYw0hSKZ5CNRtFG1RILxEW2WgdF4LEZ4nUTJTK0DV8o+XyJ+1V5N4UWSM1QcqTkyhGun7kIb/tHFKUus75LnAX7dqhhg6/ZzK8kyKzt4/FOzeKJDBLF5othKVs7SVEXMDVB6ryrYR9bXnbgn/2RxArU1v9PPs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f72.google.com with SMTP id 006d021491bc7-6a0f261aeb6so700373eaf.3 for ; Thu, 13 Aug 2026 19:50:04 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786675804; x=1787280604; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EAF6fcRr0jmp7sdqbqZ64NUQR83WASMsFOwDbghqXRw=; b=JO0p35LXxC8Nrz8FzNhMSNLcTG9vTjisH7qVLTteSO/Vi3xkbr7HoBgwf6jyXjAdhg fJlKN/XA0oOardNOdf5uoSbqBCHP7mpRrI0vh55E1xFvCmhL9O40lF3BCPCzDpDfJ1yF lgEtyC1rhLFAfpSuw/Cn5t1EeqJlohxnQU+WWv2lPjcDP3Jy2UMv/U992MxNq49S9Emp +nTC9tS7XojUf9snEA7H80iqDnJt6khxw1+EWwZt68W0/vFjW5HKdfd5PJHpAtjymUYa Hl1xnB2zXXA81g+5aMTcNFNKsfbdjaa6czPEQaNIIBsizuIiq66lEzVwPqsmfHAgYwWn 0PDg== X-Gm-Message-State: AOJu0YzRWNajjDZ+JZL1Ah8Qn3eDJFJoWfC1MPYebTWKg3wkRu+MULCk FoYMr/b85uJm3Q09egcYV4y2+hH7m+SiG1Xen0SnrGR/mbpLHe6csvmiZhHmwoqr48fYUE3Z8oP jhw2+rshSQfjsGrR79UR0hIxSkAD7czuzMEMHB4Lnv6UTLl4jqb/JyS65ARo= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:2225:b0:6ac:b3b1:a5a4 with SMTP id 006d021491bc7-6b0d5dbfea4mr2690104eaf.0.1786675803934; Thu, 13 Aug 2026 19:50:03 -0700 (PDT) Date: Thu, 13 Aug 2026 19:50:03 -0700 In-Reply-To: <6a74a76c.ec7c9571.3ac9bb.0054.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a7e825b.ec5dc6cc.21cb3f.00c1.GAE@google.com> Subject: Forwarded: [PATCH] netdevsim: update rxq->napi pointer during queue reset From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH] netdevsim: update rxq->napi pointer during queue reset Author: subasris1210@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git a59f57e2aa127c5354168d2ec4bac920df1be4f4 In netdevsim, when queue reset is performed using debugfs, it triggers these sequence of operations: nsim_queue_stop() -> nsim_queue_start() -> nsim_queue_mem_free(). nsim_queue_mem_free() frees the old nsim_rq struct which embeds the napi_struct. But the rxq->napi pointer in the struct netdev_rx_queue still points to the old nsim_rq's embedded napi_struct. So, any subsequent xsk_bind() which reads rxq->napi->napi_id after a queue reset is a use-after-free. Add netif_queue_set_napi() calls to nsim_queue_stop() and nsim_queue_start() which clears the rxq->napi during stop and sets it to the new napi instance during start. KASAN report: Call Trace: kasan_report+0xdf/0x1c0 mm/kasan/report.c:595 xsk_bind+0x1582/0x16c0 net/xdp/xsk.c:1758 __sys_bind_socket net/socket.c:1920 [inline] __sys_bind_socket net/socket.c:1912 [inline] __sys_bind+0x1a9/0x260 net/socket.c:1951 Allocated by task 5622: nsim_queue_alloc+0x3c/0x140 drivers/net/netdevsim/netdev.c:715 nsim_queue_init drivers/net/netdevsim/netdev.c:1012 [inline] nsim_init_netdevsim drivers/net/netdevsim/netdev.c:1059 [inline] nsim_create+0xb13/0x1420 drivers/net/netdevsim/netdev.c:1152 __nsim_dev_port_add+0x3ba/0x8f0 drivers/net/netdevsim/dev.c:1509 nsim_dev_port_add_all drivers/net/netdevsim/dev.c:1570 [inline] nsim_drv_probe+0xdbd/0x13a0 drivers/net/netdevsim/dev.c:1731 Freed by task 5659: slab_free mm/slub.c:6377 [inline] kfree+0x22b/0x6c0 mm/slub.c:6692 nsim_queue_mem_free+0xfe/0x190 drivers/net/netdevsim/netdev.c:796 netdev_rx_queue_reconfig+0x405/0x630 net/core/netdev_rx_queue.c:144 netdev_rx_queue_restart+0x8f/0xc0 net/core/netdev_rx_queue.c:183 nsim_qreset_write+0x2e3/0x410 drivers/net/netdevsim/netdev.c:887 Reported-by: syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=c06674caba265dc61d46 Fixes: 5bc8e8dbef27 ("netdevsim: add queue management API support") Tested-by: syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com Signed-off-by: Subasri S --- drivers/net/netdevsim/netdev.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/net/netdevsim/netdev.c b/drivers/net/netdevsim/netdev.c index 4e9d7e10b527..291d34718b2e 100644 --- a/drivers/net/netdevsim/netdev.c +++ b/drivers/net/netdevsim/netdev.c @@ -808,6 +808,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg, if (ns->rq_reset_mode == 1) { ns->rq[idx]->page_pool = qmem->pp; + netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX, + &ns->rq[idx]->napi); napi_enable_locked(&ns->rq[idx]->napi); return 0; } @@ -826,6 +828,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg, } ns->rq[idx] = qmem->rq; + netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX, + &ns->rq[idx]->napi); napi_enable_locked(&ns->rq[idx]->napi); return 0; @@ -838,6 +842,7 @@ static int nsim_queue_stop(struct net_device *dev, void *per_queue_mem, int idx) netdev_assert_locked(dev); + netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX, NULL); napi_disable_locked(&ns->rq[idx]->napi); if (ns->rq_reset_mode == 1) { -- 2.43.0