* [PATCH net v2] netlink: avoid hashing the network namespace pointer
@ 2026-10-08 1:14 Kyle Zeng
2026-10-08 1:19 ` netdev-bot+sinfo
0 siblings, 1 reply; 3+ messages in thread
From: Kyle Zeng @ 2026-10-08 1:14 UTC (permalink / raw)
To: netdev
Cc: linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures,
Kyle Zeng
The netlink rhashtable key includes a raw struct net pointer and a
user-controlled port ID. Both /proc/net/netlink and socket diagnostics
expose the table's bucket order. By binding and rebinding chosen
NETLINK_USERSOCK port IDs, an unprivileged reader can distinguish equal
buckets and recover the low bits of the Jenkins hash. Its 32-bit seed
and the limited set of kernel-image slides can then be searched offline
to recover the address of init_net.
Use the namespace's unique, non-address net_cookie in the comparison
key instead. It is assigned before the per-net initializers run and
remains unchanged for the namespace's lifetime. The lookup key and
object hash are still built by netlink_compare_arg_init(), keeping
lookup, insertion, removal and rehashing consistent while preserving
namespace separation. Neither public table walker needs to change.
Reading the socket's namespace cookie in netlink_compare() is safe
under RCU, including during namespace teardown. netlink_release()
removes the socket from the hash table and defers its final put with
call_rcu(). cleanup_net() runs the per-net exit methods and waits for
outstanding RCU callbacks with rcu_barrier() before freeing namespace
storage.
Unlike ns.ns_id, net_cookie is also available and initialized during
setup_net() in older stable kernels, making the change straightforward
to backport to v5.15 and later.
Fixes: c428ecd1a21f ("netlink: Move namespace into hash key")
Assisted-by: LLM
Signed-off-by: Kyle Zeng <kylebot@openai.com>
---
Changes in v2:
- Use net_cookie for compatibility with older stable kernels.
- Name the key field net_cookie to avoid confusion with netns IDs.
- Explain the RCU lifetime of the socket and network namespace.
net/netlink/af_netlink.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 9fdf964224ab..39db078c925c 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -464,7 +464,7 @@ netlink_unlock_table(void)
struct netlink_compare_arg
{
- possible_net_t pnet;
+ u64 net_cookie;
u32 portid;
};
@@ -479,14 +479,14 @@ static inline int netlink_compare(struct rhashtable_compare_arg *arg,
const struct netlink_sock *nlk = ptr;
return nlk->portid != x->portid ||
- !net_eq(sock_net(&nlk->sk), read_pnet(&x->pnet));
+ sock_net(&nlk->sk)->net_cookie != x->net_cookie;
}
static void netlink_compare_arg_init(struct netlink_compare_arg *arg,
struct net *net, u32 portid)
{
memset(arg, 0, sizeof(*arg));
- write_pnet(&arg->pnet, net);
+ arg->net_cookie = net->net_cookie;
arg->portid = portid;
}
base-commit: 602042bf29f6efde39cfb5fdd9289bf4854bc0c5
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v2] netlink: avoid hashing the network namespace pointer
2026-10-08 1:14 [PATCH net v2] netlink: avoid hashing the network namespace pointer Kyle Zeng
@ 2026-10-08 1:19 ` netdev-bot+sinfo
2026-10-08 1:23 ` Kyle Zeng
0 siblings, 1 reply; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-10-08 1:19 UTC (permalink / raw)
To: Kyle Zeng
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v2] netlink: avoid hashing the network namespace pointer
2026-10-08 1:19 ` netdev-bot+sinfo
@ 2026-10-08 1:23 ` Kyle Zeng
0 siblings, 0 replies; 3+ messages in thread
From: Kyle Zeng @ 2026-10-08 1:23 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
On Thu, Oct 08, 2026 at 01:19:06AM +0000, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
I have a PoC for this issue, the symptom of the issue is kernel
information leak.
Best,
Kyle
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-08 1:23 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 1:14 [PATCH net v2] netlink: avoid hashing the network namespace pointer Kyle Zeng
2026-10-08 1:19 ` netdev-bot+sinfo
2026-10-08 1:23 ` Kyle Zeng
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®