Re: [PATCH net] bridge: skip generic XDP on locally re-injected packets
From: Nikolay Aleksandrov <razor@blackwall.org>
Date: 2026-08-31 12:31:24
Also in:
bridge
On 31/08/2026 14:30, Zhao ShiRong wrote:
quoted hunk ↗ jump to hunk
Packets locally delivered by the bridge are re-injected into the receive path via br_pass_frame_up() -> br_netif_receive_skb() -> netif_receive_skb() with skb->dev set to the bridge device. If the bridge device has an XDP program attached, __netif_receive_skb_core() runs do_xdp_generic() a second time on such packets. A locally-delivered packet that was allocated on the TX path (e.g. an MLD packet built by mld_newpack()) does not carry the XDP_PACKET_HEADROOM that generic XDP requires, so netif_skb_check_for_xdp() calls pskb_expand_head() and reallocates the skb head buffer. This frees the head that the bridge rx path (br_handle_frame() / br_handle_frame_finish()) is still using, leading to a use-after-free read in br_handle_frame(): BUG: KASAN: slab-use-after-free in is_multicast_ether_addr [inline] BUG: KASAN: slab-use-after-free in is_valid_ether_addr [inline] BUG: KASAN: slab-use-after-free in br_handle_frame+0xcfb/0x1510 net/bridge/br_input.c:349 netif_receive_generic_xdp() already refuses to run generic XDP on reinjected packets by checking skb_is_redirected(). Reuse that marker: set it right before the bridge re-injects the packet, so generic XDP is skipped and the head buffer is left intact. Reported-by: syzbot+128e9f5a0f85a51215b1@syzkaller.appspotmail.com Link: https://lore.kernel.org/all/6a6d4406.2d659fcc.1d46f5.01ad.GAE@google.com/T/ (local) Signed-off-by: Zhao ShiRong <redacted> --- net/bridge/br_input.c | 6 ++++++ 1 file changed, 6 insertions(+)diff --git a/net/bridge/br_input.c b/net/bridge/br_input.c --- a/net/bridge/br_input.c +++ b/net/bridge/br_input.c@@ -26,6 +26,12 @@ static int br_netif_receive_skb(struct net *net, struct sock *sk, struct sk_buff *skb) { br_drop_fake_rtable(skb); + + /* Re-injected for local delivery: do not let generic XDP run on the + * bridge device a second time, it could reallocate the head via + * pskb_expand_head() and free a buffer still in use. + */ + skb_set_redirected_noclear(skb, false); return netif_receive_skb(skb); } --2.43.0
Nacked-by: Nikolay Aleksandrov [off-list ref] This is wrong on multiple levels, use your head for 2 seconds before blindly sending AI crap. This was sent ~2 hours after the report was sent, did you even test your patch or just hit send? Very disturbing practice anyway. Perhaps we should clone the skb for passing it up to the bridge when a fwding helper is using it (i.e. when there are actually clones).