mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
Merge branch 'tcp-fix-use-after-free-in-do_tcp_getsockopt'
Cen Zhang says: ==================== tcp: fix use-after-free in do_tcp_getsockopt() do_tcp_getsockopt() has two lockless reads of icsk_ca_ops. Since BPF struct_ops congestion control made icsk_ca_ops point to dynamically allocated memory, a concurrent setsockopt(TCP_CONGESTION) can replace the pointer and free the old object while either reader is using it. Patch 1 fixes the TCP_CONGESTION path by copying ca_ops->name to a stack buffer while holding rcu_read_lock(). It also uses READ_ONCE() for the lockless load and annotates the relevant icsk_ca_ops stores with WRITE_ONCE(). Patch 2 fixes the TCP_CC_INFO path by keeping the READ_ONCE() load, ca_ops->get_info lookup, and call inside an RCU read-side critical section. ==================== Link: https://patch.msgid.link/cover.1787870710.git.blbllhy@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
commit
b84cc38f3f
|
|
@ -4561,9 +4561,11 @@ int do_tcp_getsockopt(struct sock *sk, int level,
|
|||
if (copy_from_sockptr(&len, optlen, sizeof(int)))
|
||||
return -EFAULT;
|
||||
|
||||
ca_ops = icsk->icsk_ca_ops;
|
||||
rcu_read_lock();
|
||||
ca_ops = READ_ONCE(icsk->icsk_ca_ops);
|
||||
if (ca_ops && ca_ops->get_info)
|
||||
sz = ca_ops->get_info(sk, ~0U, &attr, &info);
|
||||
rcu_read_unlock();
|
||||
|
||||
len = min_t(unsigned int, len, sz);
|
||||
if (copy_to_sockptr(optlen, &len, sizeof(int)))
|
||||
|
|
@ -4576,16 +4578,24 @@ int do_tcp_getsockopt(struct sock *sk, int level,
|
|||
val = !inet_csk_in_pingpong_mode(sk);
|
||||
break;
|
||||
|
||||
case TCP_CONGESTION:
|
||||
case TCP_CONGESTION: {
|
||||
char ca_name[TCP_CA_NAME_MAX] = {};
|
||||
|
||||
if (copy_from_sockptr(&len, optlen, sizeof(int)))
|
||||
return -EFAULT;
|
||||
len = min_t(unsigned int, len, TCP_CA_NAME_MAX);
|
||||
if (copy_to_sockptr(optlen, &len, sizeof(int)))
|
||||
return -EFAULT;
|
||||
if (copy_to_sockptr(optval, icsk->icsk_ca_ops->name, len))
|
||||
|
||||
rcu_read_lock();
|
||||
memcpy(ca_name, READ_ONCE(icsk->icsk_ca_ops)->name,
|
||||
sizeof(ca_name));
|
||||
rcu_read_unlock();
|
||||
|
||||
if (copy_to_sockptr(optval, ca_name, len))
|
||||
return -EFAULT;
|
||||
return 0;
|
||||
|
||||
}
|
||||
case TCP_ULP:
|
||||
if (copy_from_sockptr(&len, optlen, sizeof(int)))
|
||||
return -EFAULT;
|
||||
|
|
|
|||
|
|
@ -223,7 +223,7 @@ void tcp_assign_congestion_control(struct sock *sk)
|
|||
ca = rcu_dereference(net->ipv4.tcp_congestion_control);
|
||||
if (unlikely(!bpf_try_module_get(ca, ca->owner)))
|
||||
ca = &tcp_reno;
|
||||
icsk->icsk_ca_ops = ca;
|
||||
WRITE_ONCE(icsk->icsk_ca_ops, ca);
|
||||
rcu_read_unlock();
|
||||
|
||||
memset(icsk->icsk_ca_priv, 0, sizeof(icsk->icsk_ca_priv));
|
||||
|
|
@ -253,7 +253,7 @@ static void tcp_reinit_congestion_control(struct sock *sk,
|
|||
struct inet_connection_sock *icsk = inet_csk(sk);
|
||||
|
||||
tcp_cleanup_congestion_control(sk);
|
||||
icsk->icsk_ca_ops = ca;
|
||||
WRITE_ONCE(icsk->icsk_ca_ops, ca);
|
||||
icsk->icsk_ca_setsockopt = 1;
|
||||
memset(icsk->icsk_ca_priv, 0, sizeof(icsk->icsk_ca_priv));
|
||||
|
||||
|
|
|
|||
|
|
@ -111,7 +111,7 @@ __bpf_kfunc static void dctcp_init(struct sock *sk)
|
|||
/* No ECN support? Fall back to Reno. Also need to clear
|
||||
* ECT from sk since it is set during 3WHS for DCTCP.
|
||||
*/
|
||||
inet_csk(sk)->icsk_ca_ops = &dctcp_reno;
|
||||
WRITE_ONCE(inet_csk(sk)->icsk_ca_ops, &dctcp_reno);
|
||||
INET_ECN_dontxmit(sk);
|
||||
}
|
||||
|
||||
|
|
@ -228,7 +228,7 @@ static size_t dctcp_get_info(struct sock *sk, u32 ext, int *attr,
|
|||
if (ext & (1 << (INET_DIAG_DCTCPINFO - 1)) ||
|
||||
ext & (1 << (INET_DIAG_VEGASINFO - 1))) {
|
||||
memset(&info->dctcp, 0, sizeof(info->dctcp));
|
||||
if (inet_csk(sk)->icsk_ca_ops != &dctcp_reno) {
|
||||
if (READ_ONCE(inet_csk(sk)->icsk_ca_ops) != &dctcp_reno) {
|
||||
info->dctcp.dctcp_enabled = 1;
|
||||
info->dctcp.dctcp_ce_state = (u16) ca->ce_state;
|
||||
info->dctcp.dctcp_alpha = ca->dctcp_alpha;
|
||||
|
|
|
|||
|
|
@ -507,7 +507,7 @@ void tcp_ca_openreq_child(struct sock *sk, const struct dst_entry *dst)
|
|||
ca = tcp_ca_find_key(ca_key);
|
||||
if (likely(ca && bpf_try_module_get(ca, ca->owner))) {
|
||||
icsk->icsk_ca_dst_locked = tcp_ca_dst_locked(dst);
|
||||
icsk->icsk_ca_ops = ca;
|
||||
WRITE_ONCE(icsk->icsk_ca_ops, ca);
|
||||
ca_got_dst = true;
|
||||
}
|
||||
rcu_read_unlock();
|
||||
|
|
|
|||
|
|
@ -4092,7 +4092,7 @@ static void tcp_ca_dst_init(struct sock *sk, const struct dst_entry *dst)
|
|||
if (likely(ca && bpf_try_module_get(ca, ca->owner))) {
|
||||
bpf_module_put(icsk->icsk_ca_ops, icsk->icsk_ca_ops->owner);
|
||||
icsk->icsk_ca_dst_locked = tcp_ca_dst_locked(dst);
|
||||
icsk->icsk_ca_ops = ca;
|
||||
WRITE_ONCE(icsk->icsk_ca_ops, ca);
|
||||
}
|
||||
rcu_read_unlock();
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user