tree 410f09d5fc82215511bc6ba43eedf61a2d881805
parent b54e35721f2bdc8863db5db2bd06a8173cff2011
author Eric Dumazet <edumazet@google.com> 1716896633 +0000
committer Chromeos LUCI <chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com> 1721066484 +0000

BACKPORT: net: fix __dst_negative_advice() race

__dst_negative_advice() does not enforce proper RCU rules when
sk->dst_cache must be cleared, leading to possible UAF.

RCU rules are that we must first clear sk->sk_dst_cache,
then call dst_release(old_dst).

Note that sk_dst_reset(sk) is implementing this protocol correctly,
while __dst_negative_advice() uses the wrong order.

Given that ip6_negative_advice() has special logic
against RTF_CACHE, this means each of the three ->negative_advice()
existing methods must perform the sk_dst_reset() themselves.

Note the check against NULL dst is centralized in
__dst_negative_advice(), there is no need to duplicate
it in various callbacks.

Many thanks to Clement Lecigne for tracking this issue.

This old bug became visible after the blamed commit, using UDP sockets.

Bug: 343727534
Fixes: a87cb3e48ee8 ("net: Facility to report route quality of connected sockets")
Reported-by: Clement Lecigne <clecigne@google.com>
Diagnosed-by: Clement Lecigne <clecigne@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Tom Herbert <tom@herbertland.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20240528114353.1794151-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 92f1655aa2b2294d0b49925f3b875a634bd3b59e)
[Lee: Trivial/unrelated conflict - no change to the patch]
Signed-off-by: Lee Jones <joneslee@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
(cherry picked from commit 92f1655aa2b2294d0b49925f3b875a634bd3b59e)

BUG=b:343718274
TEST=CQ

Change-Id: I2620fd289e803a92e3ac8fe21bee9ac30e1a785e
Disallow-Recycled-Builds: test-failures
Signed-off-by: Guenter Roeck <groeck@chromium.org>
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/third_party/kernel/+/5594797
Reviewed-by: Aashish Sharma <shraash@google.com>
Commit-Queue: Aashish Sharma <shraash@google.com>
(cherry picked from commit 3501b077a68f1eb0db8a3098aaf63cca71cd0bd3)
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/third_party/kernel/+/5601798
(cherry picked from commit 5810b901387494b4f242ff34edbc98ef18482a7e)
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/third_party/kernel/+/5707566
