From: Ursula Braun <redacted>
SMC ioctl processing requires the sock lock to work properly in
all thinkable scenarios.
Problem has been found with RaceFuzzer and fixes:
KASAN: null-ptr-deref Read in smc_ioctl
Reported-by: Byoungyoung Lee <redacted>
Reported-by: syzbot+35b2c5aa76fd398b9fd4@syzkaller.appspotmail.com
Signed-off-by: Ursula Braun <redacted>
---
net/smc/af_smc.c | 3 +++
1 file changed, 3 insertions(+)
@@ -1524,6 +1524,7 @@ static int smc_ioctl(struct socket *sock, unsigned int cmd,return-EBADF;returnsmc->clcsock->ops->ioctl(smc->clcsock,cmd,arg);}+lock_sock(&smc->sk);switch(cmd){caseSIOCINQ:/* same as FIONREAD */if(smc->sk.sk_state==SMC_LISTEN)
@@ -1573,8 +1574,10 @@ static int smc_ioctl(struct socket *sock, unsigned int cmd,}break;default:+release_sock(&smc->sk);return-ENOIOCTLCMD;}+release_sock(&smc->sk);returnput_user(answ,(int__user*)arg);}
From: Ursula Braun <redacted>
SMC ioctl processing requires the sock lock to work properly in
all thinkable scenarios.
Problem has been found with RaceFuzzer and fixes:
KASAN: null-ptr-deref Read in smc_ioctl
Reported-by: Byoungyoung Lee <redacted>
Reported-by: syzbot+35b2c5aa76fd398b9fd4@syzkaller.appspotmail.com
Signed-off-by: Ursula Braun <redacted>
---
net/smc/af_smc.c | 3 +++
1 file changed, 3 insertions(+)
@@ -1524,6 +1524,7 @@ static int smc_ioctl(struct socket *sock, unsigned int cmd,return-EBADF;returnsmc->clcsock->ops->ioctl(smc->clcsock,cmd,arg);}+lock_sock(&smc->sk);switch(cmd){caseSIOCINQ:/* same as FIONREAD */if(smc->sk.sk_state==SMC_LISTEN)
return -EINVAL;
you should also unlock here, and:
case SIOCOUTQ:
/* output queue size (not send + not acked) */
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here, and:
case SIOCOUTQNSD:
/* output queue size (not send only) */
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here, and:
case SIOCATMARK:
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here.
--
Stefano
From: Ursula Braun <redacted>
SMC ioctl processing requires the sock lock to work properly in
all thinkable scenarios.
Problem has been found with RaceFuzzer and fixes:
KASAN: null-ptr-deref Read in smc_ioctl
Reported-by: Byoungyoung Lee <redacted>
Reported-by: syzbot+35b2c5aa76fd398b9fd4@syzkaller.appspotmail.com
Signed-off-by: Ursula Braun <redacted>
---
net/smc/af_smc.c | 3 +++
1 file changed, 3 insertions(+)
@@ -1524,6 +1524,7 @@ static int smc_ioctl(struct socket *sock, unsigned int cmd,return-EBADF;returnsmc->clcsock->ops->ioctl(smc->clcsock,cmd,arg);}+lock_sock(&smc->sk);switch(cmd){caseSIOCINQ:/* same as FIONREAD */if(smc->sk.sk_state==SMC_LISTEN)
return -EINVAL;
you should also unlock here, and:
case SIOCOUTQ:
/* output queue size (not send + not acked) */
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here, and:
case SIOCOUTQNSD:
/* output queue size (not send only) */
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here, and:
case SIOCATMARK:
if (smc->sk.sk_state == SMC_LISTEN)
return -EINVAL;
here.
sorry, my fault! V2 is on its way. Thanks for your hint.