Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1625765
| Path | csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Andrey Konovalov <andreyknvl@google.com> |
| Newsgroups | linux.kernel |
| Subject | Re: net: heap out-of-bounds in fib6_clean_node/rt6_fill_node/fib6_age/fib6_prune_clone |
| Date | Wed, 19 Apr 2017 03:10:02 +0200 |
| Message-ID | <txMi6-57F-5@gated-at.bofh.it> (permalink) |
| References | <tgZlo-4ue-29@gated-at.bofh.it> <tiiYF-4Va-1@gated-at.bofh.it> <tikxs-66H-19@gated-at.bofh.it> <tirSi-2Tr-27@gated-at.bofh.it> <tirSi-2Tr-25@gated-at.bofh.it> <tislk-35L-15@gated-at.bofh.it> <tisOl-3ze-3@gated-at.bofh.it> <tithn-3Jt-21@gated-at.bofh.it> <titAK-46W-23@gated-at.bofh.it> <tiIT8-6v2-23@gated-at.bofh.it> <tpCfT-87G-3@gated-at.bofh.it> <tpDlE-r8-11@gated-at.bofh.it> <tpDOF-Ur-9@gated-at.bofh.it> <txIet-2fd-9@gated-at.bofh.it> <txKJk-3Uf-17@gated-at.bofh.it> |
| X-Original-To | David Ahern <dsa@cumulusnetworks.com> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=JFAuJHkLWp0kcYTu1izojnlpXtcpp7NZ8PyW2TVvVUo=; b=iVlASmFSxFKBpzwPJodK7/TZbqUmZGE86tvhKc3j+ImjIfbbWTbO2wkDKZCfpl7Caz jF3smiB6KrRnFX/vQebueS2Q4CB0fDYa/YAP59P85OpCg5LuNaVacLgm5PSzutPWvmJn 7fdBYs+ZwdCGsz0EhOeYFeMXAXrOFlN5cqy6uNJSdi5tEr+fKiQ7PiyJ8RLzYoG9I0dc 5TY0qnLWky9LOQ2o6s9GrKCtTqFISprLgSIwsTVu3oRo13W99j2knNNjGU6/HACLHlPw vmuHEDR7JdT/lUrLC09J4OsJ4J5D2e2SbcgKmfg+XKFXCP9TPDAcKo3acYLiZttjF4Qb QNFg== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=JFAuJHkLWp0kcYTu1izojnlpXtcpp7NZ8PyW2TVvVUo=; b=lxqVxCy/nEbA9rOshtMLVjaiWjY6EzNKPdXgm95FIpHoCH8Rnl8YHXdRmxQxzCDNOC FtJjLht7U7a1LeVwiFSUBXV+uwvZVTqUXenxVlCdQgazc5fWYeOF8+pES5lNHvgEqGPD sjhqfcb0l/eoKPKdrgfHMmHHKOklXy4wwJUskIldzfn4I28lgpmlvIDfrXed2z9R2LNl 2rXsrjXvwMrN8vTrdDkQwmGgA49LDlg7yoBT56KQ3mipEK+e4AUQxhEX7hOwjyAnp5UI PoUdxJ7mI359o0Rs3t45f4J7PO+AR2LwABGC0eWw60uznhoOYrMwYb0sltuvh+QdIvOl HAkw== |
| X-Gm-Message-State | AN3rC/7ntnuKysv6GV9HehlUMbPrjeHT1o7ay73ukOTl8Ii+VSQAu5We 8WIrRkc0G7GWBWeictvKDEmshU8ho0g3 |
| X-Received | by 10.99.104.199 with SMTP id d190mr288881pgc.141.1492564142438; Tue, 18 Apr 2017 18:09:02 -0700 (PDT) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=UTF-8 |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 52 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | Dmitry Vyukov <dvyukov@google.com>, Eric Dumazet <eric.dumazet@gmail.com>, Mahesh Bandewar <maheshb@google.com>, Eric Dumazet <edumazet@google.com>, David Miller <davem@davemloft.net>, Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>, James Morris <jmorris@namei.org>, Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>, Patrick McHardy <kaber@trash.net>, netdev <netdev@vger.kernel.org>, LKML <linux-kernel@vger.kernel.org>, Cong Wang <xiyou.wangcong@gmail.com>, syzkaller <syzkaller@googlegroups.com> |
| X-Original-Date | Wed, 19 Apr 2017 03:09:01 +0200 |
| X-Original-Message-ID | <CAAeHK+y_GutDu+yQa74DFBrwnxmgGWOyMFyO4CTfFnD9V5bUBQ@mail.gmail.com> |
| X-Original-References | <CACT4Y+YrA45diWz_8f4St8oX6aTC1kuGXMUvniGRbqXSGwawZQ@mail.gmail.com> <CACT4Y+aomj0W8M9JNr1GLsT8EFFHV9YsOTYzWkvwKZANE9hiBQ@mail.gmail.com> <CACT4Y+aDzAYs9mbNGeFEkYSB2wTwomZTGEKn4hDH0PAb4uiLqw@mail.gmail.com> <2b60b1b8-4766-0e36-f6fb-79914bf1925d@cumulusnetworks.com> <CACT4Y+YpUZ+7f5bzPh1hATwUXaZaPTu4rYYdz0RY1MHA1WG3SA@mail.gmail.com> <328b1fa7-2d97-6ae3-3b87-e33a0d564ad9@cumulusnetworks.com> <CACT4Y+aQFe+M=ESuShQ4FYNWAd8CNEQ=0rW+aAB0P-tp=PpFyQ@mail.gmail.com> <CACT4Y+aQgM=9QMkyfcXF2B5gGidvL07JP_m_inNXTPXU22i=aA@mail.gmail.com> <CACT4Y+Yx1cgWCkC2c7bze1V1VaecgBfioMvKS2-FUeaRr4DGXg@mail.gmail.com> <CACT4Y+bcMz13ad2kLaZGvct5sQ+RDki0StnOEbz3exAa8=zxqQ@mail.gmail.com> <CACT4Y+Z6f4aOxMZW44WXdYEyDJbGBYLnjKsHBXfK800h+EkrxA@mail.gmail.com> <2270c1ca-9481-60c1-9c29-87669223bded@cumulusnetworks.com> <CACT4Y+aUROZgAczRfntp5Rgvzcypviz5ZWBPdE6MWSiO0-3jEg@mail.gmail.com> <CAAeHK+zx6W_yxnoEQ2Pc1AT4uLXqYZaoi5oQBeuCntdGS38TQg@mail.gmail.com> <732d29dc-0240-cd1a-6973-5d14636ceaee@cumulusnetworks.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1625765 |
Show key headers only | View raw
On Wed, Apr 19, 2017 at 1:20 AM, David Ahern <dsa@cumulusnetworks.com> wrote:
> On 4/18/17 2:43 PM, Andrey Konovalov wrote:
>> I've finally managed to reproduce one of the crashes on commit
>> 4f7d029b9bf009fbee76bb10c0c4351a1870d2f3 (4.11-rc7).
>>
>> I'm not sure if this bug has the same root cause as the first one
>> reported in this thread, but it definitely has to do with ipv6
>> routing.
>>
>> C reproducer, syzkaller program and my .config are attached.
Just FYI, the reproducer uses interface number 9 inside a user
namespace, which is apparently ip6gre0.
1: lo: <LOOPBACK> mtu 65536 qdisc noop state DOWN mode DEFAULT qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: tunl0@NONE: <NOARP> mtu 1480 qdisc noop state DOWN mode DEFAULT qlen 1000
link/ipip 0.0.0.0 brd 0.0.0.0
3: gre0@NONE: <NOARP> mtu 1476 qdisc noop state DOWN mode DEFAULT qlen 1000
link/gre 0.0.0.0 brd 0.0.0.0
4: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN
mode DEFAULT qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
5: ip_vti0@NONE: <NOARP> mtu 1332 qdisc noop state DOWN mode DEFAULT qlen 1000
link/ipip 0.0.0.0 brd 0.0.0.0
6: ip6_vti0@NONE: <NOARP> mtu 1500 qdisc noop state DOWN mode DEFAULT qlen 1000
link/tunnel6 :: brd ::
7: sit0@NONE: <NOARP> mtu 1480 qdisc noop state DOWN mode DEFAULT qlen 1000
link/sit 0.0.0.0 brd 0.0.0.0
8: ip6tnl0@NONE: <NOARP> mtu 1452 qdisc noop state DOWN mode DEFAULT qlen 1000
link/tunnel6 :: brd ::
9: ip6gre0@NONE: <NOARP> mtu 1448 qdisc noop state DOWN mode DEFAULT qlen 1000
link/[823] 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 brd
00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
>>
>> Thanks!
>>
>> kasan: CONFIG_KASAN_INLINE enabled
>> kasan: GPF could be caused by NULL-ptr deref or user memory access
>> general protection fault: 0000 [#1] SMP KASAN
>> Modules linked in:
>> CPU: 1 PID: 4035 Comm: a.out Not tainted 4.11.0-rc7+ #250
>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
>> task: ffff880069809600 task.stack: ffff880062dc8000
>> RIP: 0010:ip6_rt_cache_alloc+0xa6/0x560 net/ipv6/route.c:975
>
> From a quick glance seems to be a different bug than Dmitry's.
It might be.
>
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: net: heap out-of-bounds in fib6_clean_node/rt6_fill_node/fib6_age/fib6_prune_clone David Ahern <dsa@cumulusnetworks.com> - 2017-04-19 01:30 +0200 Re: net: heap out-of-bounds in fib6_clean_node/rt6_fill_node/fib6_age/fib6_prune_clone Andrey Konovalov <andreyknvl@google.com> - 2017-04-19 03:10 +0200
csiph-web