Thread (2 messages) flat view 2 messages, 2 authors, 2018-08-13

Re: [PATCH net v2] l2tp: use sk_dst_check() to avoid race on sk->sk_dst_cache

From: David Miller <davem@davemloft.net>
Date: 2018-08-13 18:31:50

From: Wei Wang <redacted>
Date: Fri, 10 Aug 2018 11:14:56 -0700
From: Wei Wang <redacted>

In l2tp code, if it is a L2TP_UDP_ENCAP tunnel, tunnel->sk points to a
UDP socket. User could call sendmsg() on both this tunnel and the UDP
socket itself concurrently. As l2tp_xmit_skb() holds socket lock and call
__sk_dst_check() to refresh sk->sk_dst_cache, while udpv6_sendmsg() is
lockless and call sk_dst_check() to refresh sk->sk_dst_cache, there
could be a race and cause the dst cache to be freed multiple times.
So we fix l2tp side code to always call sk_dst_check() to garantee
xchg() is called when refreshing sk->sk_dst_cache to avoid race
conditions.

Syzkaller reported stack trace:
 ...
Fixes: 71b1391a4128 ("l2tp: ensure sk->dst is still valid")
Reported-by: syzbot+05f840f3b04f211bad55@syzkaller.appspotmail.com
Signed-off-by: Wei Wang <redacted>
Signed-off-by: Martin KaFai Lau <redacted>
 ...
---
v1->v2: Removed dst_clone() as Guillaume Nault suggested
Applied and queued up for -stable, thank you.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help