Thread (10 messages) flat view 10 messages, 3 authors, 2012-06-19

Re: [PATCH] ipv6: Prevent access to uninitialized fib_table_hash via /proc/net/ipv6_route

From: David Miller <davem@davemloft.net>
Date: 2012-06-16 05:15:06

From: David Miller <davem@davemloft.net>
Date: Fri, 15 Jun 2012 15:32:40 -0700 (PDT)
From: Neil Horman <nhorman@tuxdriver.com>
Date: Fri, 15 Jun 2012 06:56:55 -0400
quoted
On Fri, Jun 15, 2012 at 11:00:17AM +0200, Thomas Graf wrote:
quoted
/proc/net/ipv6_route reflects the contents of fib_table_hash. The proc
handler is installed in ip6_route_net_init() whereas fib_table_hash is
allocated in fib6_net_init() _after_ the proc handler has been installed.

This opens up a short time frame to access fib_table_hash with its pants
down.

fib6_init() as a whole can't be moved to an earlier position as it also
registers the rtnetlink message handlers which should be registered at
the end. Therefore split it into fib6_init() which is run early and
fib6_init_late() to register the rtnetlink message handlers.

Signed-off-by: Thomas Graf <tgraf@suug.ch>
Reviewed-by: Neil Horman <nhorman@tuxdriver.com>
Applied.

Since you're snooping around in here, you might notice that on network
namespace shutdown, we leak all user configured ipv6 FIB rules.
Thomas, this patch is buggy.

We will now initialize fib6_init() before ip6_net_route_net_ops is registerd.

This causes fib6_net_init() to run before net->ipv6.ip6_null_entry it
initialized.

Any route lookup will crash when we dereference a root's ->leaf
because it will be NULL.

Please test your changes more thoroughly.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help