mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ziyang Xuan <william.xuanziyang@huawei.com>
To: <davem@davemloft.net>, <kuba@kernel.org>, <pabeni@redhat.com>,
	<netdev@vger.kernel.org>
Cc: <edumazet@google.com>, <brianvv@google.com>,
	<linux-kernel@vger.kernel.org>
Subject: [PATCH net-next v3 0/3] net: ipvlan: fix potential UAF problem for phy_dev
Date: Sat, 19 Mar 2022 17:52:00 +0800	[thread overview]
Message-ID: <cover.1647664114.git.william.xuanziyang@huawei.com> (raw)

There is a known scenario can trigger UAF problem for lower
netdevice as following:

Someone module puts the NETDEV_UNREGISTER event handler to a
work, and lower netdevice is accessed in the work handler. But
when the work is excuted, lower netdevice has been destroyed
because upper netdevice did not get reference to lower netdevice
correctly.

Although it can not happen for ipvlan now because there is no
way to access phy_dev outside ipvlan. But it is necessary to
add the reference operation to phy_dev to avoid the potential
UAF problem in the future.

In addition, add net device refcount tracker to ipvlan and
fix some error comments for ipvtap module.

---
v2->v3:
  - Make it clear that the problem can not happen now but for future.
  - Delete "Fixes: tag" to avoid backporting to stable.
v1->v2:
  - Add "Fixes: tag" for fix patches.

Ziyang Xuan (3):
  net: ipvlan: fix potential UAF problem for phy_dev
  net: ipvlan: add net device refcount tracker
  net: ipvtap: fix error comments

 drivers/net/ipvlan/ipvlan.h      |  1 +
 drivers/net/ipvlan/ipvlan_main.c | 13 +++++++++++++
 drivers/net/ipvlan/ipvtap.c      |  4 ++--
 3 files changed, 16 insertions(+), 2 deletions(-)

-- 
2.25.1


             reply	other threads:[~2022-03-19  9:34 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-03-19  9:52 Ziyang Xuan [this message]
2022-03-19  9:52 ` [PATCH net-next v3 1/3] " Ziyang Xuan
2022-03-22 14:03   ` Eric Dumazet
2022-03-19  9:53 ` [PATCH net-next v3 2/3] net: ipvlan: add net device refcount tracker Ziyang Xuan
2022-03-22 14:01   ` Eric Dumazet
2022-03-19  9:53 ` [PATCH net-next v3 3/3] net: ipvtap: fix error comments Ziyang Xuan
2022-03-22  9:15 ` [PATCH net-next v3 0/3] net: ipvlan: fix potential UAF problem for phy_dev Paolo Abeni

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1647664114.git.william.xuanziyang@huawei.com \
    --to=william.xuanziyang@huawei.com \
    --cc=brianvv@google.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®