mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 20:53:03 +02:00
netfilter: nfnetlink_log: cope with concurrent instance destruction
Instances are refcounted. However, only memory release happens on the
1 -> 0 transition; the unlink from hashes can occur with any refcount.
Uncooperative userspace can force a situation where a queue is pending
for destruction from netlink event while a different socket with same
portid processes an UNBIND request.
With right timing, this will unhash the instance again:
Oops: general protection fault, [..]
Call Trace:
<TASK>
nfulnl_recv_config+0x31a/0xd50
nfnetlink_rcv_msg+0x7c2/0xeb0
Fixes: 0597f2680d ("[NETFILTER]: Add new "nfnetlink_log" userspace packet logging facility")
Reported-by: Eulgyu Kim <eulgyukim@snu.ac.kr>
Reported-by: Jaeyoung Chung <jjy600901@snu.ac.kr>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
2c018cc484
commit
387d744fa7
|
|
@ -228,13 +228,18 @@ static void __nfulnl_flush(struct nfulnl_instance *inst);
|
|||
static void
|
||||
__instance_destroy(struct nfulnl_instance *inst)
|
||||
{
|
||||
spin_lock(&inst->lock);
|
||||
if (inst->copy_mode == NFULNL_COPY_DISABLED) {
|
||||
/* attempt to UNBIND a queue already pending
|
||||
* destruction via netlink close event. Ignore.
|
||||
*/
|
||||
spin_unlock(&inst->lock);
|
||||
return;
|
||||
}
|
||||
|
||||
/* first pull it out of the global list */
|
||||
hlist_del_rcu(&inst->hlist);
|
||||
|
||||
/* then flush all pending packets from skb */
|
||||
|
||||
spin_lock(&inst->lock);
|
||||
|
||||
/* lockless readers wont be able to use us */
|
||||
inst->copy_mode = NFULNL_COPY_DISABLED;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user