mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-14 06:22:34 +02:00
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()
and free the old skb head, leaving ip6h dangling; the following
get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()
uses ip6h (and the iaddr derived from it) again after the csum-adjust
call and additionally writes the new locator through that pointer.
Impact: a remote IPv6 packet routed through a configured ILA
csum-adjust-transport route or receive-side mapping triggers a
slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or
mapping requires CAP_NET_ADMIN to configure, but trigger packets are
unauthenticated once it exists.
Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()
before the csum-diff read. In ila_update_ipv6_locator() only the
ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in
that case alone before the destination-address write; the neutral-map
modes never pull and keep their cached pointers.
Fixes: 33f11d1614 ("ila: Create net/ipv6/ila directory")
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Reviewed-by: Antoine Tenart <atenart@kernel.org>
Link: https://patch.msgid.link/20260714114903.3763420-1-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
169 lines
4.3 KiB
C
169 lines
4.3 KiB
C
// SPDX-License-Identifier: GPL-2.0
|
|
#include <linux/errno.h>
|
|
#include <linux/ip.h>
|
|
#include <linux/kernel.h>
|
|
#include <linux/module.h>
|
|
#include <linux/skbuff.h>
|
|
#include <linux/socket.h>
|
|
#include <linux/types.h>
|
|
#include <net/checksum.h>
|
|
#include <net/ip.h>
|
|
#include <net/ip6_fib.h>
|
|
#include <net/lwtunnel.h>
|
|
#include <net/protocol.h>
|
|
#include <uapi/linux/ila.h>
|
|
#include "ila.h"
|
|
|
|
void ila_init_saved_csum(struct ila_params *p)
|
|
{
|
|
if (!p->locator_match.v64)
|
|
return;
|
|
|
|
p->csum_diff = compute_csum_diff8(
|
|
(__be32 *)&p->locator,
|
|
(__be32 *)&p->locator_match);
|
|
}
|
|
|
|
static __wsum get_csum_diff_iaddr(struct ila_addr *iaddr, struct ila_params *p)
|
|
{
|
|
if (p->locator_match.v64)
|
|
return p->csum_diff;
|
|
else
|
|
return compute_csum_diff8((__be32 *)&p->locator,
|
|
(__be32 *)&iaddr->loc);
|
|
}
|
|
|
|
static __wsum get_csum_diff(struct ipv6hdr *ip6h, struct ila_params *p)
|
|
{
|
|
return get_csum_diff_iaddr(ila_a2i(&ip6h->daddr), p);
|
|
}
|
|
|
|
static void ila_csum_do_neutral_fmt(struct ila_addr *iaddr,
|
|
struct ila_params *p)
|
|
{
|
|
__sum16 *adjust = (__force __sum16 *)&iaddr->ident.v16[3];
|
|
__wsum diff, fval;
|
|
|
|
diff = get_csum_diff_iaddr(iaddr, p);
|
|
|
|
fval = (__force __wsum)(ila_csum_neutral_set(iaddr->ident) ?
|
|
CSUM_NEUTRAL_FLAG : ~CSUM_NEUTRAL_FLAG);
|
|
|
|
diff = csum_add(diff, fval);
|
|
|
|
*adjust = ~csum_fold(csum_add(diff, csum_unfold(*adjust)));
|
|
|
|
/* Flip the csum-neutral bit. Either we are doing a SIR->ILA
|
|
* translation with ILA_CSUM_NEUTRAL_MAP as the csum_method
|
|
* and the C-bit is not set, or we are doing an ILA-SIR
|
|
* tranlsation and the C-bit is set.
|
|
*/
|
|
iaddr->ident.csum_neutral ^= 1;
|
|
}
|
|
|
|
static void ila_csum_do_neutral_nofmt(struct ila_addr *iaddr,
|
|
struct ila_params *p)
|
|
{
|
|
__sum16 *adjust = (__force __sum16 *)&iaddr->ident.v16[3];
|
|
__wsum diff;
|
|
|
|
diff = get_csum_diff_iaddr(iaddr, p);
|
|
|
|
*adjust = ~csum_fold(csum_add(diff, csum_unfold(*adjust)));
|
|
}
|
|
|
|
static void ila_csum_adjust_transport(struct sk_buff *skb,
|
|
struct ila_params *p)
|
|
{
|
|
size_t nhoff = sizeof(struct ipv6hdr);
|
|
struct ipv6hdr *ip6h = ipv6_hdr(skb);
|
|
__wsum diff;
|
|
|
|
switch (ip6h->nexthdr) {
|
|
case NEXTHDR_TCP:
|
|
if (likely(pskb_may_pull(skb, nhoff + sizeof(struct tcphdr)))) {
|
|
struct tcphdr *th = (struct tcphdr *)
|
|
(skb_network_header(skb) + nhoff);
|
|
|
|
ip6h = ipv6_hdr(skb);
|
|
diff = get_csum_diff(ip6h, p);
|
|
inet_proto_csum_replace_by_diff(&th->check, skb,
|
|
diff, true, true);
|
|
}
|
|
break;
|
|
case NEXTHDR_UDP:
|
|
if (likely(pskb_may_pull(skb, nhoff + sizeof(struct udphdr)))) {
|
|
struct udphdr *uh = (struct udphdr *)
|
|
(skb_network_header(skb) + nhoff);
|
|
|
|
if (uh->check || skb->ip_summed == CHECKSUM_PARTIAL) {
|
|
ip6h = ipv6_hdr(skb);
|
|
diff = get_csum_diff(ip6h, p);
|
|
inet_proto_csum_replace_by_diff(&uh->check, skb,
|
|
diff, true, true);
|
|
if (!uh->check)
|
|
uh->check = CSUM_MANGLED_0;
|
|
}
|
|
}
|
|
break;
|
|
case NEXTHDR_ICMP:
|
|
if (likely(pskb_may_pull(skb,
|
|
nhoff + sizeof(struct icmp6hdr)))) {
|
|
struct icmp6hdr *ih = (struct icmp6hdr *)
|
|
(skb_network_header(skb) + nhoff);
|
|
|
|
ip6h = ipv6_hdr(skb);
|
|
diff = get_csum_diff(ip6h, p);
|
|
inet_proto_csum_replace_by_diff(&ih->icmp6_cksum, skb,
|
|
diff, true, true);
|
|
}
|
|
break;
|
|
}
|
|
}
|
|
|
|
void ila_update_ipv6_locator(struct sk_buff *skb, struct ila_params *p,
|
|
bool sir2ila)
|
|
{
|
|
struct ipv6hdr *ip6h = ipv6_hdr(skb);
|
|
struct ila_addr *iaddr = ila_a2i(&ip6h->daddr);
|
|
|
|
switch (p->csum_mode) {
|
|
case ILA_CSUM_ADJUST_TRANSPORT:
|
|
ila_csum_adjust_transport(skb, p);
|
|
/*
|
|
* ila_csum_adjust_transport() calls pskb_may_pull(), which can
|
|
* reallocate the skb head and leave ip6h (and the iaddr derived
|
|
* from it) dangling; reload both before the write below. The
|
|
* other csum modes do not pull, so their cached pointers stay
|
|
* valid.
|
|
*/
|
|
ip6h = ipv6_hdr(skb);
|
|
iaddr = ila_a2i(&ip6h->daddr);
|
|
break;
|
|
case ILA_CSUM_NEUTRAL_MAP:
|
|
if (sir2ila) {
|
|
if (WARN_ON(ila_csum_neutral_set(iaddr->ident))) {
|
|
/* Checksum flag should never be
|
|
* set in a formatted SIR address.
|
|
*/
|
|
break;
|
|
}
|
|
} else if (!ila_csum_neutral_set(iaddr->ident)) {
|
|
/* ILA to SIR translation and C-bit isn't
|
|
* set so we're good.
|
|
*/
|
|
break;
|
|
}
|
|
ila_csum_do_neutral_fmt(iaddr, p);
|
|
break;
|
|
case ILA_CSUM_NEUTRAL_MAP_AUTO:
|
|
ila_csum_do_neutral_nofmt(iaddr, p);
|
|
break;
|
|
case ILA_CSUM_NO_ACTION:
|
|
break;
|
|
}
|
|
|
|
/* Now change destination address */
|
|
iaddr->loc = p->locator;
|
|
}
|