From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 13:58:54
Hello Jakub, hello David,
this is a pull request of 3 patches for net/master.
All three patches are by Vincent Mailhol and fix a potential use after free bug
in the CAN device infrastructure, the vxcan driver, and the peak_usk driver. In
the TX-path the skb is used to read from after it was passed to the networking
stack with netif_rx_ni().
Note: Patch 1/3 touches "drivers/net/can/dev.c". In net-next/master this file
has been moved to drivers/net/can/dev/dev.c [1] and parts of it have been
transfered into separate files. This may result in a merge conflict. Please
carry this patch forward, the change is rather simple. Drop us a note if
needed. Are any actions needed with regards to linux-next?
[1] 3e77f70e7345 can: dev: move driver related infrastructure into separate subdir
regards,
Marc
---
The following changes since commit 9c30ae8398b0813e237bde387d67a7f74ab2db2d:
tcp: fix TCP socket rehash stats mis-accounting (2021-01-19 19:47:20 -0800)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can.git tags/linux-can-fixes-for-5.11-20210120
for you to fetch changes up to 50aca891d7a554db0901b245167cd653d73aaa71:
can: peak_usb: fix use after free bugs (2021-01-20 13:33:28 +0100)
----------------------------------------------------------------
linux-can-fixes-for-5.11-20210120
----------------------------------------------------------------
Vincent Mailhol (3):
can: dev: can_restart: fix use after free bug
can: vxcan: vxcan_xmit: fix use after free bug
can: peak_usb: fix use after free bugs
drivers/net/can/dev.c | 4 ++--
drivers/net/can/usb/peak_usb/pcan_usb_fd.c | 8 ++++----
drivers/net/can/vxcan.c | 6 ++++--
3 files changed, 10 insertions(+), 8 deletions(-)
From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 13:58:55
From: Vincent Mailhol <redacted>
After calling netif_rx_ni(skb), dereferencing skb is unsafe.
Especially, the can_frame cf which aliases skb memory is accessed
after the netif_rx_ni() in:
stats->rx_bytes += cf->len;
Reordering the lines solves the issue.
Fixes: 39549eef3587 ("can: CAN Network device driver and Netlink interface")
Link: https://lore.kernel.org/r/20210120114137.200019-2-mailhol.vincent@wanadoo.fr
Signed-off-by: Vincent Mailhol <redacted>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
drivers/net/can/dev.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
From: Jakub Kicinski <kuba@kernel.org> Date: 2021-01-20 17:21:51
On Wed, 20 Jan 2021 13:51:59 +0100 Marc Kleine-Budde wrote:
Hello Jakub, hello David,
this is a pull request of 3 patches for net/master.
All three patches are by Vincent Mailhol and fix a potential use after free bug
in the CAN device infrastructure, the vxcan driver, and the peak_usk driver. In
the TX-path the skb is used to read from after it was passed to the networking
stack with netif_rx_ni().
Pulled, thanks.
Seems like the PR didn't show up in patchwork at all :S Hopefully I can
still pull reight manually without the scripts :)
Note: Patch 1/3 touches "drivers/net/can/dev.c". In net-next/master this file
has been moved to drivers/net/can/dev/dev.c [1] and parts of it have been
transfered into separate files. This may result in a merge conflict. Please
carry this patch forward, the change is rather simple. Drop us a note if
needed. Are any actions needed with regards to linux-next?
Thanks for the note, I'm sending the PR to Linus now, so I think
linux-next may never see the the conflict.
From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 20:22:58
On 1/20/21 6:19 PM, Jakub Kicinski wrote:
quoted
this is a pull request of 3 patches for net/master.
All three patches are by Vincent Mailhol and fix a potential use after free bug
in the CAN device infrastructure, the vxcan driver, and the peak_usk driver. In
the TX-path the skb is used to read from after it was passed to the networking
stack with netif_rx_ni().
Pulled, thanks.
Seems like the PR didn't show up in patchwork at all :S Hopefully I can
still pull reight manually without the scripts :)
Fingers crossed. :D
Today I noticed a lag of >4h on vger.kernel.org. Even this mail of yours hasn't
made it to the linux-can list, yet. It's 3h delayed.
quoted
Note: Patch 1/3 touches "drivers/net/can/dev.c". In net-next/master this file
has been moved to drivers/net/can/dev/dev.c [1] and parts of it have been
transfered into separate files. This may result in a merge conflict. Please
carry this patch forward, the change is rather simple. Drop us a note if
needed. Are any actions needed with regards to linux-next?
Thanks for the note, I'm sending the PR to Linus now, so I think
linux-next may never see the the conflict.
thanks,
Marc
--
Pengutronix e.K. | Marc Kleine-Budde |
Embedded Linux | https://www.pengutronix.de |
Vertretung West/Dortmund | Phone: +49-231-2826-924 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |
From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 20:26:09
From: Vincent Mailhol <redacted>
After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe.
Especially, the can_frame cf which aliases skb memory is accessed
after the peak_usb_netif_rx_ni().
Reordering the lines solves the issue.
Fixes: 0a25e1f4f185 ("can: peak_usb: add support for PEAK new CANFD USB adapters")
Link: https://lore.kernel.org/r/20210120114137.200019-4-mailhol.vincent@wanadoo.fr
Signed-off-by: Vincent Mailhol <redacted>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
drivers/net/can/usb/peak_usb/pcan_usb_fd.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
From: Jakub Kicinski <kuba@kernel.org> Date: 2021-01-20 20:42:09
On Wed, 20 Jan 2021 21:20:13 +0100 Marc Kleine-Budde wrote:
On 1/20/21 6:19 PM, Jakub Kicinski wrote:
quoted
quoted
this is a pull request of 3 patches for net/master.
All three patches are by Vincent Mailhol and fix a potential use after free bug
in the CAN device infrastructure, the vxcan driver, and the peak_usk driver. In
the TX-path the skb is used to read from after it was passed to the networking
stack with netif_rx_ni().
Pulled, thanks.
Seems like the PR didn't show up in patchwork at all :S Hopefully I can
still pull reight manually without the scripts :)
Fingers crossed. :D
Today I noticed a lag of >4h on vger.kernel.org. Even this mail of yours hasn't
made it to the linux-can list, yet. It's 3h delayed.
It's been reported but it's unclear what's causing this one :(
quoted
quoted
Note: Patch 1/3 touches "drivers/net/can/dev.c". In net-next/master this file
has been moved to drivers/net/can/dev/dev.c [1] and parts of it have been
transfered into separate files. This may result in a merge conflict. Please
carry this patch forward, the change is rather simple. Drop us a note if
needed. Are any actions needed with regards to linux-next?
Thanks for the note, I'm sending the PR to Linus now, so I think
linux-next may never see the the conflict.
The merge has been done now, could you double check?
Hello:
This series was applied to netdev/net-next.git (refs/heads/master):
On Wed, 20 Jan 2021 13:52:00 +0100 you wrote:
From: Vincent Mailhol <redacted>
After calling netif_rx_ni(skb), dereferencing skb is unsafe.
Especially, the can_frame cf which aliases skb memory is accessed
after the netif_rx_ni() in:
stats->rx_bytes += cf->len;
[...]
Hello:
This pull request was applied to netdev/net-next.git (refs/heads/master):
On Wed, 20 Jan 2021 13:51:59 +0100 you wrote:
Hello Jakub, hello David,
this is a pull request of 3 patches for net/master.
All three patches are by Vincent Mailhol and fix a potential use after free bug
in the CAN device infrastructure, the vxcan driver, and the peak_usk driver. In
the TX-path the skb is used to read from after it was passed to the networking
stack with netif_rx_ni().
[...]
From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 20:50:35
From: Vincent Mailhol <redacted>
After calling netif_rx_ni(skb), dereferencing skb is unsafe.
Especially, the canfd_frame cfd which aliases skb memory is accessed
after the netif_rx_ni().
Fixes: a8f820a380a2 ("can: add Virtual CAN Tunnel driver (vxcan)")
Link: https://lore.kernel.org/r/20210120114137.200019-3-mailhol.vincent@wanadoo.fr
Signed-off-by: Vincent Mailhol <redacted>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
drivers/net/can/vxcan.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
From: Marc Kleine-Budde <mkl@pengutronix.de> Date: 2021-01-20 22:12:30
On 1/20/21 9:36 PM, Jakub Kicinski wrote:
quoted
quoted
quoted
Note: Patch 1/3 touches "drivers/net/can/dev.c". In net-next/master this file
has been moved to drivers/net/can/dev/dev.c [1] and parts of it have been
transfered into separate files. This may result in a merge conflict. Please
carry this patch forward, the change is rather simple. Drop us a note if
needed. Are any actions needed with regards to linux-next?
Thanks for the note, I'm sending the PR to Linus now, so I think
linux-next may never see the the conflict.
The merge has been done now, could you double check?
Looks good!
Thanks,
Marc
--
Pengutronix e.K. | Marc Kleine-Budde |
Embedded Linux | https://www.pengutronix.de |
Vertretung West/Dortmund | Phone: +49-231-2826-924 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |