Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1462288
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.2 75/94] batman-adv: Fix use-after-free/double-free of tt_req_node |
| Date | 2016-08-14 20:20 +0200 |
| Message-ID | <s68aS-35C-59@gated-at.bofh.it> (permalink) |
| References | <s5LnX-4sk-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
3.2.82-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Sven Eckelmann <sven@narfation.org>
commit 9c4604a298e0a9807eaf2cd912d1ebf24d98fbeb upstream.
The tt_req_node is added and removed from a list inside a spinlock. But the
locking is sometimes removed even when the object is still referenced and
will be used later via this reference. For example batadv_send_tt_request
can create a new tt_req_node (including add to a list) and later
re-acquires the lock to remove it from the list and to free it. But at this
time another context could have already removed this tt_req_node from the
list and freed it.
CPU#0
batadv_batman_skb_recv from net_device 0
-> batadv_iv_ogm_receive
-> batadv_iv_ogm_process
-> batadv_iv_ogm_process_per_outif
-> batadv_tvlv_ogm_receive
-> batadv_tvlv_ogm_receive
-> batadv_tvlv_containers_process
-> batadv_tvlv_call_handler
-> batadv_tt_tvlv_ogm_handler_v1
-> batadv_tt_update_orig
-> batadv_send_tt_request
-> batadv_tt_req_node_new
spin_lock(...)
allocates new tt_req_node and adds it to list
spin_unlock(...)
return tt_req_node
CPU#1
batadv_batman_skb_recv from net_device 1
-> batadv_recv_unicast_tvlv
-> batadv_tvlv_containers_process
-> batadv_tvlv_call_handler
-> batadv_tt_tvlv_unicast_handler_v1
-> batadv_handle_tt_response
spin_lock(...)
tt_req_node gets removed from list and is freed
spin_unlock(...)
CPU#0
<- returned to batadv_send_tt_request
spin_lock(...)
tt_req_node gets removed from list and is freed
MEMORY CORRUPTION/SEGFAULT/...
spin_unlock(...)
This can only be solved via reference counting to allow multiple contexts
to handle the list manipulation while making sure that only the last
context holding a reference will free the object.
Fixes: a73105b8d4c7 ("batman-adv: improved client announcement mechanism")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Tested-by: Martin Weinelt <martin@darmstadt.freifunk.net>
Tested-by: Amadeus Alfa <amadeus@chemnitz.freifunk.net>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2:
- Adjust context
- Use struct tt_req_node instead of struct batadv_tt_req_node
- Use list_empty() instead of hlist_unhashed()
- Drop kernel-doc change]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
net/batman-adv/translation-table.c | 43 ++++++++++++++++++++++++++++++++------
net/batman-adv/types.h | 2 ++
2 files changed, 39 insertions(+), 6 deletions(-)
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -952,6 +952,29 @@ uint16_t tt_local_crc(struct bat_priv *b
return total;
}
+/**
+ * batadv_tt_req_node_release - free tt_req node entry
+ * @ref: kref pointer of the tt req_node entry
+ */
+static void batadv_tt_req_node_release(struct kref *ref)
+{
+ struct tt_req_node *tt_req_node;
+
+ tt_req_node = container_of(ref, struct tt_req_node, refcount);
+
+ kfree(tt_req_node);
+}
+
+/**
+ * batadv_tt_req_node_put - decrement the tt_req_node refcounter and
+ * possibly release it
+ * @tt_req_node: tt_req_node to be free'd
+ */
+static void batadv_tt_req_node_put(struct tt_req_node *tt_req_node)
+{
+ kref_put(&tt_req_node->refcount, batadv_tt_req_node_release);
+}
+
static void tt_req_list_free(struct bat_priv *bat_priv)
{
struct tt_req_node *node, *safe;
@@ -960,7 +983,7 @@ static void tt_req_list_free(struct bat_
list_for_each_entry_safe(node, safe, &bat_priv->tt_req_list, list) {
list_del(&node->list);
- kfree(node);
+ batadv_tt_req_node_put(node);
}
spin_unlock_bh(&bat_priv->tt_req_list_lock);
@@ -995,7 +1018,7 @@ static void tt_req_purge(struct bat_priv
if (is_out_of_time(node->issued_at,
TT_REQUEST_TIMEOUT * 1000)) {
list_del(&node->list);
- kfree(node);
+ batadv_tt_req_node_put(node);
}
}
spin_unlock_bh(&bat_priv->tt_req_list_lock);
@@ -1020,9 +1043,11 @@ static struct tt_req_node *new_tt_req_no
if (!tt_req_node)
goto unlock;
+ kref_init(&tt_req_node->refcount);
memcpy(tt_req_node->addr, orig_node->orig, ETH_ALEN);
tt_req_node->issued_at = jiffies;
+ kref_get(&tt_req_node->refcount);
list_add(&tt_req_node->list, &bat_priv->tt_req_list);
unlock:
spin_unlock_bh(&bat_priv->tt_req_list_lock);
@@ -1174,12 +1199,19 @@ out:
hardif_free_ref(primary_if);
if (ret)
kfree_skb(skb);
+
if (ret && tt_req_node) {
spin_lock_bh(&bat_priv->tt_req_list_lock);
- list_del(&tt_req_node->list);
+ if (!list_empty(&tt_req_node->list)) {
+ list_del(&tt_req_node->list);
+ batadv_tt_req_node_put(tt_req_node);
+ }
spin_unlock_bh(&bat_priv->tt_req_list_lock);
- kfree(tt_req_node);
}
+
+ if (tt_req_node)
+ batadv_tt_req_node_put(tt_req_node);
+
return ret;
}
@@ -1552,7 +1584,7 @@ void handle_tt_response(struct bat_priv
if (!compare_eth(node->addr, tt_response->src))
continue;
list_del(&node->list);
- kfree(node);
+ batadv_tt_req_node_put(node);
}
spin_unlock_bh(&bat_priv->tt_req_list_lock);
--- a/net/batman-adv/types.h
+++ b/net/batman-adv/types.h
@@ -250,6 +250,7 @@ struct tt_change_node {
struct tt_req_node {
uint8_t addr[ETH_ALEN];
unsigned long issued_at;
+ struct kref refcount;
struct list_head list;
};
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH 3.2 00/94] 3.2.82-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 26/94] fs/cifs: correctly to anonymous authentication for the LANMAN authentication Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 23/94] x86/PCI: Mark Broadwell-EP Home Agent 1 as having non-compliant BARs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 93/94] tcp: make challenge acks less predictable Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:50 +0200 [PATCH 3.2 62/94] UBIFS: Implement ->migratepage() Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 42/94] x86, build: copy ldlinux.c32 to image.iso Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 54/94] kvm: Fix irq route entries exceeding KVM_MAX_IRQ_ROUTES Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 13/94] USB: serial: option: add even more ZTE device ids Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 35/94] Input: xpad - prevent spurious input from wired Xbox 360 controllers Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 43/94] fix d_walk()/non-delayed __d_free() race Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 18/94] powerpc/mm/hash64: Factor out hash preload psize check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:00 +0200 [PATCH 3.2 86/94] proc: prevent stacking filesystems on top Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 34/94] RDMA/cxgb3: device driver frees DMA memory with different size Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 22/94] net/mlx4_core: Fix access to uninitialized index Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 82/94] xenbus: don't BUG() on user mode induced condition Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 69/94] ALSA: dummy: Fix a use-after-free at closing Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 74/94] NFS: Fix another OPEN_DOWNGRADE bug Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 73/94] ALSA: echoaudio: Fix memory allocation Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 61/94] mm: Export migrate_page_move_mapping and migrate_page_copy Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 [PATCH 3.2 02/94] ath5k: Change led pin configuration for compaq c700 laptop Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 14:10 +0200 Re: [PATCH 3.2 00/94] 3.2.82-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-08-14 17:10 +0200 [PATCH 3.2 39/94] ARM: fix PTRACE_SETVFPREGS on SMP systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 85/94] fs: limit filesystem stacking depth Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 11/94] tty: vt, return error when con_startup fails Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 91/94] tipc: fix an infoleak in tipc_nl_compat_link_dump Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 15/94] MIPS: Adjust set_pte() SMP fix to handle R10000_LLSC_WAR Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 60/94] ubi: Make recover_peb power cut aware Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 03/94] crypto: s5p-sss - Fix missed interrupts when working with 8 kB blocks Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 64/94] xen/pciback: Fix conf_space read/write overlap check. Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 25/94] fs/cifs: correctly to anonymous authentication via NTLMSSP Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:00 +0200 [PATCH 3.2 37/94] Input: pwm-beeper - fix - scheduling while atomic Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 21/94] mmc: mmc: Fix partition switch timeout for some eMMCs Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 88/94] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 01/94] regmap: cache: Fix typo in cache_bypass parameter description Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 63/94] can: fix oops caused by wrong rtnl dellink usage Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 77/94] x86/amd_nb: Fix boot crash on non-AMD systems Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 79/94] bonding: prevent out of bound accesses Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 06/94] crypto: s5p-sss - fix incorrect usage of scatterlists api Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 59/94] can: at91_can: RX queue could get stuck at high bus load Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 70/94] fs/nilfs2: fix potential underflow in call to crc32_le Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 71/94] staging: iio: accel: fix error check Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 84/94] cifs: dynamic allocation of ntlmssp blob Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 52/94] kernel/sysrq, watchdog, sched/core: Reset watchdog on all CPUs while processing sysrq-w Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 40/94] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 53/94] base: make module_create_drivers_dir race-free Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:10 +0200 [PATCH 3.2 87/94] USB: usbfs: fix potential infoleak in devio Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 48/94] staging:iio: trigger fixes for repeat request of same trigger and allocation failure Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 09/94] ext4: fix hang when processing corrupted orphaned inode list Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200 [PATCH 3.2 75/94] batman-adv: Fix use-after-free/double-free of tt_req_node Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 20:20 +0200
csiph-web