Eric Dumazet
c4c857723b
net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()
...
[ Upstream commit b0ec2abf98267f14d032102551581c833b0659d3 ]
Apply the same fix than ones found in :
8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()")
1ca1ba465e55 ("geneve: make sure to pull inner header in geneve_rx()")
We have to save skb->network_header in a temporary variable
in order to be able to recompute the network_header pointer
after a pskb_inet_may_pull() call.
pskb_inet_may_pull() makes sure the needed headers are in skb->head.
syzbot reported:
BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
BUG: KMSAN: uninit-value in IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]
BUG: KMSAN: uninit-value in ip_tunnel_rcv+0xed9/0x2ed0 net/ipv4/ip_tunnel.c:409
__INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]
ip_tunnel_rcv+0xed9/0x2ed0 net/ipv4/ip_tunnel.c:409
__ipgre_rcv+0x9bc/0xbc0 net/ipv4/ip_gre.c:389
ipgre_rcv net/ipv4/ip_gre.c:411 [inline]
gre_rcv+0x423/0x19f0 net/ipv4/ip_gre.c:447
gre_rcv+0x2a4/0x390 net/ipv4/gre_demux.c:163
ip_protocol_deliver_rcu+0x264/0x1300 net/ipv4/ip_input.c:205
ip_local_deliver_finish+0x2b8/0x440 net/ipv4/ip_input.c:233
NF_HOOK include/linux/netfilter.h:314 [inline]
ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254
dst_input include/net/dst.h:461 [inline]
ip_rcv_finish net/ipv4/ip_input.c:449 [inline]
NF_HOOK include/linux/netfilter.h:314 [inline]
ip_rcv+0x46f/0x760 net/ipv4/ip_input.c:569
__netif_receive_skb_one_core net/core/dev.c:5534 [inline]
__netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5648
netif_receive_skb_internal net/core/dev.c:5734 [inline]
netif_receive_skb+0x58/0x660 net/core/dev.c:5793
tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1556
tun_get_user+0x53b9/0x66e0 drivers/net/tun.c:2009
tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2055
call_write_iter include/linux/fs.h:2087 [inline]
new_sync_write fs/read_write.c:497 [inline]
vfs_write+0xb6b/0x1520 fs/read_write.c:590
ksys_write+0x20f/0x4c0 fs/read_write.c:643
__do_sys_write fs/read_write.c:655 [inline]
__se_sys_write fs/read_write.c:652 [inline]
__x64_sys_write+0x93/0xd0 fs/read_write.c:652
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
Uninit was created at:
__alloc_pages+0x9a6/0xe00 mm/page_alloc.c:4590
alloc_pages_mpol+0x62b/0x9d0 mm/mempolicy.c:2133
alloc_pages+0x1be/0x1e0 mm/mempolicy.c:2204
skb_page_frag_refill+0x2bf/0x7c0 net/core/sock.c:2909
tun_build_skb drivers/net/tun.c:1686 [inline]
tun_get_user+0xe0a/0x66e0 drivers/net/tun.c:1826
tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2055
call_write_iter include/linux/fs.h:2087 [inline]
new_sync_write fs/read_write.c:497 [inline]
vfs_write+0xb6b/0x1520 fs/read_write.c:590
ksys_write+0x20f/0x4c0 fs/read_write.c:643
__do_sys_write fs/read_write.c:655 [inline]
__se_sys_write fs/read_write.c:652 [inline]
__x64_sys_write+0x93/0xd0 fs/read_write.c:652
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
Fixes: c54419321455 ("GRE: Refactor GRE tunneling code.")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:19:39 -04:00
..
2024-01-01 12:42:41 +00:00
2024-01-31 16:19:01 -08:00
2023-12-20 17:01:50 +01:00
2023-12-20 17:01:48 +01:00
2023-09-18 12:56:58 +01:00
2023-08-24 10:51:39 -07:00
2024-03-26 18:19:38 -04:00
2024-02-05 20:14:20 +00:00
2023-05-31 13:06:57 +02:00
2024-03-06 14:48:36 +00:00
2023-06-24 15:50:13 -07:00
2024-02-23 09:25:17 +01:00
2024-03-01 13:34:56 +01:00
2024-03-26 18:19:34 -04:00
2023-08-01 21:07:46 -07:00
2023-11-20 11:59:35 +01:00
2024-03-01 13:35:09 +01:00
2024-01-25 15:35:41 -08:00
2023-08-09 13:08:09 -07:00
2024-01-25 15:36:00 -08:00
2024-02-23 09:24:50 +01:00
2024-03-06 14:48:36 +00:00
2023-08-29 17:39:15 -07:00
2024-01-01 12:42:30 +00:00
2024-03-26 18:19:39 -04:00
2024-03-26 18:19:39 -04:00
2024-03-26 18:19:12 -04:00
2024-02-05 20:14:25 +00:00
2023-08-18 12:44:56 -07:00
2024-03-01 13:35:01 +01:00
2024-02-05 20:14:36 +00:00
2024-03-26 18:19:13 -04:00
2023-06-24 15:41:46 -07:00
2024-03-26 18:19:34 -04:00
2023-08-15 15:26:18 -07:00
2024-03-06 14:48:42 +00:00
2024-01-25 15:35:20 -08:00
2024-03-15 10:48:19 -04:00
2024-01-25 15:35:14 -08:00
2024-03-06 14:48:34 +00:00
2024-03-15 10:48:21 -04:00
2024-02-23 09:25:02 +01:00
2023-06-10 00:11:41 -07:00
2024-02-23 09:24:51 +01:00
2023-12-13 18:45:23 +01:00
2024-03-01 13:35:10 +01:00
2023-12-13 18:45:10 +01:00
2024-01-20 11:51:47 +01:00
2024-03-15 10:48:18 -04:00
2024-01-01 12:42:41 +00:00
2024-01-01 12:42:31 +00:00
2024-02-16 19:10:50 +01:00
2024-03-01 13:35:09 +01:00
2024-01-25 15:35:30 -08:00
2024-02-05 20:14:25 +00:00
2024-03-26 18:19:36 -04:00
2024-03-01 13:35:06 +01:00
2024-02-16 19:10:50 +01:00
2024-03-06 14:48:37 +00:00
2024-03-26 18:19:23 -04:00
2024-01-25 15:35:26 -08:00
2024-03-06 14:48:40 +00:00
2023-06-24 15:50:13 -07:00
2024-03-01 13:35:05 +01:00
2024-03-26 18:19:15 -04:00
2023-04-14 11:09:27 +01:00
2023-07-19 10:07:27 -07:00
2023-04-19 18:48:48 -07:00
2024-01-10 17:16:51 +01:00
2023-08-15 15:26:17 -07:00