linux/net
Dairui Zhang 56d82862a0 af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
prb_calc_retire_blk_tmo() computes in 32-bit int arithmetic:

        mbits = (blk_size_in_bytes * 8) / (1024 * 1024);

If I'm reading the validation right, tp_block_size is user
controlled and packet_set_ring() only rejects values that are <= 0
as int or not page aligned, so a 256MiB block goes right through
(and alloc_one_pg_vec_page() even has a vzalloc fallback for it).
0x10000000 * 8 wraps to INT_MIN, and on a NIC reporting 1 Gbps
(div == 1) the function ends up returning -2047.

The condition is actually (8 * size) mod 2^32 >= 2^31 && div == 1,
so the trigger set is [256,512), [768,1024), [1280,1536) and
[1792,2048) MiB. Other sizes wrap to non-negative values and faster
links divide the unsigned value back below 2^31, which is why this
doesn't blow up for everyone.

What makes it fatal is what happens next in init_prb_bdqc():

        p1->interval_ktime = ms_to_ktime(prb_calc_retire_blk_tmo(...));
        hrtimer_start(&p1->retire_blk_timer, p1->interval_ktime,
                      HRTIMER_MODE_REL_SOFT);

A negative relative timeout expires immediately. The callback
unconditionally returns HRTIMER_RESTART, and hrtimer_forward() turns
the negative interval into hrtimer_resolution:

        if (interval < hrtimer_resolution)
                interval = hrtimer_resolution;

So the SOFT timer re-fires at the maximum rate forever, holding
sk_receive_queue.lock each pass. One CPU spins in softirq until the
socket is closed. Repeat with more rings and the machine is gone.

The overflow itself is ancient - it was introduced together with
TPACKET_V3 in f6fb8f100b ("af-packet: TPACKET_V3 flexible buffer
implementation."). Its effect prior to f7460d2989 ("net:
af_packet: Use hrtimer to do the retire operation", v6.18) was not
as clear-cut, though: the return value was stored into an unsigned
short retire_blk_tov, so a negative result was truncated, and a
0-jiffy delay loop could be programmed as well. Neither is nearly
as detrimental as the immediate maximum-rate spin the hrtimer
conversion turned it into.

(Unrelated to CVE-2019-20812 - that one was the ethtool failure path
returning 0, which now returns DEFAULT_PRB_RETIRE_TOV.)

Reproducer, needs CAP_NET_RAW (a --network host container has it by
default) and a 1 Gbps NIC (QEMU e1000 works):

        int fd = socket(AF_PACKET, SOCK_RAW, htons(ETH_P_ALL));
        bind(fd, ...);
        int v = TPACKET_V3;
        setsockopt(fd, SOL_PACKET, PACKET_VERSION, &v, sizeof(v));
        struct tpacket_req3 req = {
                .tp_block_size = 0x10000000,
                .tp_block_nr = 1,
                .tp_frame_size = 2048,
                .tp_frame_nr = 0x10000000 / 2048,
                .tp_retire_blk_tov = 0,
        };
        setsockopt(fd, SOL_PACKET, PACKET_RX_RING, &req, sizeof(req));

Compute in 64 bits instead. The operands are already bounded by the
existing validation, so nothing else changes. If you'd prefer a
different fix, just say so and I'll respin.

Fixes: f6fb8f100b ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Dairui Zhang <zhangdairui@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260923050101.1510064-1-zhangdairui@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-24 10:40:50 -07:00
..
6lowpan net: 6lowpan: fix mismatched comments 2026-09-02 09:03:06 +02:00
9p 9p: Add missing read barrier in virtio zero-copy path 2026-06-21 05:22:57 +00:00
802 appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
8021q vlan: fix skb_under_panic and races when toggling HW VLAN offload 2026-08-20 13:05:43 -07:00
atm pppoatm: ensure a writable skb header and linear data 2026-09-15 17:07:01 -07:00
batman-adv treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
bluetooth Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() 2026-09-21 09:37:20 -04:00
bpf bpf: Fix partial copy of non-linear test_run output 2026-06-21 17:55:06 -07:00
bridge net: bridge: mdb: restart port group walk after deletion 2026-09-23 16:51:03 -07:00
can can: isotp: check register_netdevice_notifier() error in module init 2026-07-29 11:26:41 +02:00
ceph libceph: remove pinning assertion in ceph_msg_data_iter_next() 2026-09-02 12:23:05 +02:00
core net: xps: reject an out of range traffic class 2026-09-23 19:39:38 -07:00
dcb
devlink treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
dns_resolver keys, dns: Drop unused NUL terminator from upayload->data 2026-08-10 16:20:42 -07:00
dsa net: dsa: tag_brcm: legacy FCS: request needed tailroom 2026-09-09 13:31:08 -07:00
ethernet
ethtool net: ethtool: keep rtnl_lock for the ioctl self test 2026-09-18 17:19:15 -07:00
handshake handshake: Require admin permission for DONE command 2026-06-12 15:45:44 -07:00
hsr net: hsr: enable promiscuous mode on interlink port with fwd offload 2026-09-10 08:45:00 -07:00
ieee802154 ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink 2026-09-02 09:54:27 +02:00
ife net/sched: act_ife: Only operate on Ethernet frames 2026-08-24 11:59:59 -07:00
ipv4 tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() 2026-09-24 09:17:10 -07:00
ipv6 ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST 2026-09-23 18:34:13 -07:00
iucv net/iucv: fix the recvmsg window update 2026-08-31 15:51:22 -07:00
kcm net: kcm: Hold RCU read lock while running BPF parser 2026-08-17 13:43:58 -07:00
key ipsec-2026-06-22 2026-06-23 16:22:24 -07:00
l2tp net: l2tp: do not propagate multicast notification errors 2026-08-24 11:43:28 -07:00
l3mdev
lapb
llc llc: fix SAP refcount leak when creating incoming sockets 2026-07-17 13:17:46 +02:00
mac80211 Many fixes: 2026-09-16 15:54:56 -07:00
mac802154 mac802154: fix use-after-free of sdata via queued RX frames 2026-09-03 11:00:54 +02:00
mctp mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag() 2026-09-24 09:11:56 -07:00
mpls Summary 2026-08-20 08:46:41 -07:00
mptcp mptcp: fix bad accounting in __mptcp_subflow_push_pending() 2026-09-17 08:14:33 -07:00
ncsi net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length 2026-08-05 17:24:57 -07:00
netfilter netfilter: nf_tables: skip expired catchall elements on insert and delete 2026-09-18 11:24:05 +02:00
netlabel Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-06-11 14:33:35 -07:00
netlink genetlink: report the real command id for dump-only ops in policy dumps 2026-09-22 15:21:32 +02:00
nfc nfc: llcp: fix slab-out-of-bounds reads when logging service names 2026-09-23 22:13:17 +02:00
nsh
openvswitch net: openvswitch: conntrack: fix helper UAF due to extensions realloc 2026-09-24 09:56:01 -07:00
packet af_packet: fix integer overflow in prb_calc_retire_blk_tmo() 2026-09-24 10:40:50 -07:00
phonet phonet: pep: convert getsockopt to sockopt_t 2026-08-03 16:55:23 -07:00
psample net: psample: fix info leak in PSAMPLE_ATTR_DATA 2026-06-17 16:35:50 -07:00
psp net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() 2026-09-16 19:18:24 -07:00
qrtr net: qrtr: Send HELLO message on endpoint register 2026-09-02 12:14:32 +01:00
rds net/rds: size a connection's path set by the transport it ends up with 2026-09-24 10:03:23 -07:00
rfkill Replace <linux/mod_devicetable.h> by more specific <linux/device-id/*.h> (c files) 2026-07-03 07:38:17 +02:00
rxrpc treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
sched net/sched: act_ct: fix helper UAF due to extensions realloc 2026-09-24 09:56:02 -07:00
sctp sctp: hold asoc or transport before mod_timer() in timer handlers 2026-09-22 18:36:36 -07:00
shaper net: shaper: add a note that we expect cap dumps to be tiny 2026-06-11 12:55:23 +02:00
smc net/smc: fix UAF on lgr list traversal in smcr_port_err() 2026-09-24 10:19:50 -07:00
strparser
sunrpc treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
switchdev
tipc tipc: Fix a data race on mon->peer_cnt in mon_timeout() 2026-09-24 10:21:45 -07:00
tls tls: device: fix out-of-bounds write in tls_append_frag() 2026-08-25 10:04:02 +02:00
unix af_unix: Unify scc_index when finalising SCC in __unix_walk_scc(). 2026-09-15 16:45:05 -07:00
vmw_vsock vsock: ignore empty child namespace mode writes 2026-09-17 19:06:31 -07:00
wireless Many fixes: 2026-09-16 15:54:56 -07:00
x25 net/x25: fix use-after-free of the socket by its timers 2026-07-30 18:46:45 -07:00
xdp xsk: honor XDP_TX_METADATA in zero-copy path 2026-08-24 11:12:00 -07:00
xfrm ipsec-2026-09-16 2026-09-16 15:54:19 -07:00
compat.c net: af_unix: useful handling of LSM denials on SCM_RIGHTS 2026-08-17 18:14:52 -07:00
devres.c
Kconfig appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
Kconfig.debug
Makefile appletalk: move the protocol out of tree 2026-06-16 14:37:06 -07:00
socket.c Major changes: 2026-08-20 07:36:20 -07:00
sysctl_net.c net: enforce net sysctl registration 2026-08-13 13:12:21 +02:00