linux/net/tipc
Eric Dumazet 99cc2a62e0 tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
Commit 48a5fe3877 ("tipc: fix bc_ackers underflow on duplicate
GRP_ACK_MSG") rejected duplicate/stale ACKs in tipc_group_proto_rcv()
by returning early when less_eq(acked, m->bc_acked).

However, that check remains incomplete in two ways:

1. When grp->bc_ackers is zero (e.g. on a quiet group, when replicast
   ACKs were not requested, or after all expected members have already
   acknowledged), an unexpected GRP_ACK_MSG with acked > m->bc_acked
   passes less_eq() and unconditionally decrements grp->bc_ackers.
   Because bc_ackers is a u16, this wraps to 65535, causing
   tipc_group_bc_cong() to permanently report congestion and blocking
   all future group broadcasts on the socket.

2. During an active broadcast round (grp->bc_ackers > 0), the sender
   transmits packet S and advances grp->bc_snd_nxt to S + 1. Receivers
   increment their expected counter to S + 1 upon consuming packet S,
   so the only valid ACK value for the current round is strictly
   acked == grp->bc_snd_nxt.

   However, tipc_group_update_bc_members() initializes each member's
   m->bc_acked to prev = grp->bc_snd_nxt - 1 (S - 1 before increment).
   This leaves a 2-sequence gap (S - 1 to S + 1) in sequence space.
   An incoming ACK is therefore neither rejected as duplicate nor
   prevented from decrementing grp->bc_ackers if an unexpected or stale
   value (such as S) is received. A member sending acked = S followed
   by acked = S + 1 could decrement grp->bc_ackers twice in the same
   round, prematurely clearing bc_ackers or underflowing it.

Fix this by:
- Dropping GRP_ACK_MSG immediately if grp->bc_ackers is zero.
- Requiring acked == grp->bc_snd_nxt and rejecting duplicates where
  m->bc_acked == acked. Because replicast broadcast rounds are strictly
  sequential, only grp->bc_snd_nxt can be acknowledged, and each member
  can acknowledge at most once per round.

Note that a related pre-existing issue in tipc_group_delete_member()
(where grp->bc_ackers decrementing to zero upon member departure does
not restore *grp->open or trigger a socket wakeup) will be addressed
in a separate patch.

Fixes: 48a5fe3877 ("tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG")
Fixes: 2f487712b8 ("tipc: guarantee that group broadcast doesn't bypass group unicast")
Reported-by: James Burton <jamesburton@meta.com>
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260913044233.193927-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-18 15:42:47 -07:00
..
addr.c tipc: adjust tipc_nodeid2string() to return string length 2025-09-30 11:22:39 +02:00
addr.h tipc: adjust tipc_nodeid2string() to return string length 2025-09-30 11:22:39 +02:00
bcast.c tipc: fix out-of-bounds read in broadcast Gap ACK blocks 2026-06-29 17:30:20 -07:00
bcast.h tipc: fix out-of-bounds read in broadcast Gap ACK blocks 2026-06-29 17:30:20 -07:00
bearer.c tipc: fix UAF in tipc_l2_send_msg() 2026-06-15 12:50:29 -07:00
bearer.h
core.c tipc: avoid busy looping in tipc_exit_net() 2026-06-25 08:53:00 -07:00
core.h kernel.h: drop hex.h and update all hex.h users 2026-01-20 19:44:19 -08:00
crypto.c tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done 2026-06-18 18:35:35 -07:00
crypto.h
diag.c
discover.c tipc: fix use-after-free of the discoverer in tipc_disc_rcv() 2026-06-21 14:28:22 -07:00
discover.h
eth_media.c
group.c tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow 2026-09-18 15:42:47 -07:00
group.h
ib_media.c
Kconfig ipv6: convert CONFIG_IPV6 to built-in only and clean up Kconfigs 2026-03-29 11:21:22 -07:00
link.c tipc: Dont send random pad bytes in RESET/ACTIVATE messages 2026-08-31 20:02:36 -07:00
link.h
Makefile
monitor.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
monitor.h
msg.c tipc: fix double-free in tipc_buf_append() 2026-04-23 11:45:01 -07:00
msg.h
name_distr.c tipc: reject inverted service ranges from peer bindings 2026-06-11 16:01:16 -07:00
name_distr.h
name_table.c tipc: fix NULL deref in tipc_named_node_up() on empty publication list 2026-08-31 20:01:49 -07:00
name_table.h net: tipc: remove one synchronize_net() from tipc_nametbl_stop() 2024-12-06 17:41:28 -08:00
net.c tipc: Fix use-after-free in tipc_mon_reinit_self(). 2025-11-10 18:14:40 -08:00
net.h
netlink_compat.c tipc: fix infinite loop in __tipc_nl_compat_dumpit 2026-07-21 15:12:23 -07:00
netlink.c tipc: fix u16 MTU truncation in media and bearer MTU validation 2026-07-23 11:41:03 +02:00
netlink.h
node.c tipc: protect node reset trace dump with node lock 2026-08-28 14:35:19 -07:00
node.h
socket.c tipc: avoid use-after-free in poll trace queue dumps 2026-07-27 15:18:59 -07:00
socket.h
subscr.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
subscr.h
sysctl.c net: Remove ctl_table sentinel elements from several networking subsystems 2024-05-03 13:29:42 +01:00
topsrv.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
topsrv.h
trace.c
trace.h tracing/treewide: Remove second parameter of __assign_str() 2024-05-22 20:14:47 -04:00
udp_media.c tipc: serialize udp bearer replicast list updates 2026-07-21 11:57:21 -07:00
udp_media.h