Thread (4 messages) flat view 4 messages, 4 authors, 2018-07-16

Re: [PATCH net] tun: Fix use-after-free on XDP_TX

From: Jesper Dangaard Brouer <hidden>
Date: 2018-07-13 06:10:17

On Fri, 13 Jul 2018 13:05:04 +0800
Jason Wang [off-list ref] wrote:
On 2018年07月13日 12:24, Toshiaki Makita wrote:
quoted
On XDP_TX we need to free up the frame only when tun_xdp_tx() returns a
negative value. A positive value indicates that the packet is
successfully enqueued to the ptr_ring, so freeing the page causes
use-after-free.

Fixes: 735fc4054b3a ("xdp: change ndo_xdp_xmit API to support bulking")
Signed-off-by: Toshiaki Makita <redacted>
---
  drivers/net/tun.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index a192a01..f5727ba 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -1688,7 +1688,7 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun,
  		case XDP_TX:
  			get_page(alloc_frag->page);
  			alloc_frag->offset += buflen;
-			if (tun_xdp_tx(tun->dev, &xdp))
+			if (tun_xdp_tx(tun->dev, &xdp) < 0)
  				goto err_redirect;
  			rcu_read_unlock();
  			local_bh_enable();  
Acked-by: Jason Wang <redacted>
Acked-by: Jesper Dangaard Brouer <redacted>

Thanks for catching and fixing this!

-- 
Best regards,
  Jesper Dangaard Brouer
  MSc.CS, Principal Kernel Engineer at Red Hat
  LinkedIn: http://www.linkedin.com/in/brouer
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help