mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
bridge: mcast: Fix a possible use-after-free when removing a bridge port
[ Upstream commit4df78ff026] When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. The reverse happens when multicast snooping is disabled. The above scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled on a single bridge port: # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge mcast_vlan_snooping 1 # ip link set dev br1 type bridge mcast_snooping 0 # ip link set dev br1 type bridge mcast_snooping 1 This is not intended and it is a problem since the commit cited below. Prior to this commit, when removing a bridge port, br_multicast_disable_port() would disable the per-port multicast context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs. After this commit, br_multicast_disable_port() only disables the per-port multicast context if per-VLAN multicast snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1]. Fix by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global multicast snooping if per-VLAN multicast snooping is enabled. [1] ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0 [...] Call Trace: <IRQ> __debug_check_no_obj_freed (lib/debugobjects.c:1116) kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobject_cleanup (lib/kobject.c:689) rcu_do_batch (kernel/rcu/tree.c:2617) rcu_core (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irq_exit_rcu (kernel/softirq.c:752) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ> Fixes:4b30ae9adb("net: bridge: mcast: re-implement br_multicast_{enable, disable}_port functions") Reported-by: syzbot+ae231e0552fa77b26ea1@syzkaller.appspotmail.com Closes: https://lore.kernel.org/netdev/87qznowlfs.ffs@tglx/ Reported-by: Thomas Gleixner <tglx@kernel.org> Acked-by: Nikolay Aleksandrov <nikolay@nvidia.com> Signed-off-by: Ido Schimmel <idosch@nvidia.com> Link: https://patch.msgid.link/20260517121122.188333-2-idosch@nvidia.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
6e79715b7b
commit
1900ca8acb
@@ -4641,10 +4641,24 @@ static void br_multicast_start_querier(struct net_bridge_mcast *brmctx,
|
||||
rcu_read_unlock();
|
||||
}
|
||||
|
||||
static void br_multicast_del_grps(struct net_bridge *br)
|
||||
static void br_multicast_enable_all_ports(struct net_bridge *br)
|
||||
{
|
||||
struct net_bridge_port *port;
|
||||
|
||||
if (br_opt_get(br, BROPT_MCAST_VLAN_SNOOPING_ENABLED))
|
||||
return;
|
||||
|
||||
list_for_each_entry(port, &br->port_list, list)
|
||||
__br_multicast_enable_port_ctx(&port->multicast_ctx);
|
||||
}
|
||||
|
||||
static void br_multicast_disable_all_ports(struct net_bridge *br)
|
||||
{
|
||||
struct net_bridge_port *port;
|
||||
|
||||
if (br_opt_get(br, BROPT_MCAST_VLAN_SNOOPING_ENABLED))
|
||||
return;
|
||||
|
||||
list_for_each_entry(port, &br->port_list, list)
|
||||
__br_multicast_disable_port_ctx(&port->multicast_ctx);
|
||||
}
|
||||
@@ -4652,7 +4666,6 @@ static void br_multicast_del_grps(struct net_bridge *br)
|
||||
int br_multicast_toggle(struct net_bridge *br, unsigned long val,
|
||||
struct netlink_ext_ack *extack)
|
||||
{
|
||||
struct net_bridge_port *port;
|
||||
bool change_snoopers = false;
|
||||
int err = 0;
|
||||
|
||||
@@ -4669,7 +4682,7 @@ int br_multicast_toggle(struct net_bridge *br, unsigned long val,
|
||||
br_opt_toggle(br, BROPT_MULTICAST_ENABLED, !!val);
|
||||
if (!br_opt_get(br, BROPT_MULTICAST_ENABLED)) {
|
||||
change_snoopers = true;
|
||||
br_multicast_del_grps(br);
|
||||
br_multicast_disable_all_ports(br);
|
||||
goto unlock;
|
||||
}
|
||||
|
||||
@@ -4677,8 +4690,7 @@ int br_multicast_toggle(struct net_bridge *br, unsigned long val,
|
||||
goto unlock;
|
||||
|
||||
br_multicast_open(br);
|
||||
list_for_each_entry(port, &br->port_list, list)
|
||||
__br_multicast_enable_port_ctx(&port->multicast_ctx);
|
||||
br_multicast_enable_all_ports(br);
|
||||
|
||||
change_snoopers = true;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user