[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20171124.012716.1134458426501486126.davem@davemloft.net>
Date: Fri, 24 Nov 2017 01:27:16 +0900 (KST)
From: David Miller <davem@...emloft.net>
To: code@...pl.cz
Cc: netdev@...r.kernel.org
Subject: Re: [PATCH v2] net: sched: fix crash when deleting secondary chains
From: Roman Kapl <code@...pl.cz>
Date: Mon, 20 Nov 2017 22:21:13 +0100
> If you flush (delete) a filter chain other than chain 0 (such as when
> deleting the device), the kernel may run into a use-after-free. The
> chain refcount must not be decremented unless we are sure we are done
> with the chain.
>
> To reproduce the bug, run:
> ip link add dtest type dummy
> tc qdisc add dev dtest ingress
> tc filter add dev dtest chain 1 parent ffff: flower
> ip link del dtest
>
> Introduced in: commit f93e1cdcf42c ("net/sched: fix filter flushing"),
> but unless you have KAsan or luck, you won't notice it until
> commit 0dadc117ac8b ("cls_flower: use tcf_exts_get_net() before call_rcu()")
>
> Fixes: f93e1cdcf42c ("net/sched: fix filter flushing")
> Acked-by: Jiri Pirko <jiri@...lanox.com>
> Signed-off-by: Roman Kapl <code@...pl.cz>
Applied, thank you.
Powered by blists - more mailing lists