All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	stable@vger.kernel.org,
	syzbot+5f1a04e374a635efc426@syzkaller.appspotmail.com,
	Kirill Tkhai <ktkhai@virtuozzo.com>,
	"David S. Miller" <davem@davemloft.net>
Subject: [PATCH 4.9 14/31] kcm: Fix use-after-free caused by clonned sockets
Date: Tue, 12 Jun 2018 18:46:17 +0200	[thread overview]
Message-ID: <20180612164621.360578922@linuxfoundation.org> (raw)
In-Reply-To: <20180612164620.797338191@linuxfoundation.org>

4.9-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kirill Tkhai <ktkhai@virtuozzo.com>

[ Upstream commit eb7f54b90bd8f469834c5e86dcf72ebf9a629811 ]

(resend for properly queueing in patchwork)

kcm_clone() creates kernel socket, which does not take net counter.
Thus, the net may die before the socket is completely destructed,
i.e. kcm_exit_net() is executed before kcm_done().

Reported-by: syzbot+5f1a04e374a635efc426@syzkaller.appspotmail.com
Signed-off-by: Kirill Tkhai <ktkhai@virtuozzo.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/kcm/kcmsock.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/kcm/kcmsock.c
+++ b/net/kcm/kcmsock.c
@@ -1671,7 +1671,7 @@ static struct file *kcm_clone(struct soc
 	__module_get(newsock->ops->owner);
 
 	newsk = sk_alloc(sock_net(osock->sk), PF_KCM, GFP_KERNEL,
-			 &kcm_proto, true);
+			 &kcm_proto, false);
 	if (!newsk) {
 		sock_release(newsock);
 		return ERR_PTR(-ENOMEM);



  parent reply	other threads:[~2018-06-12 17:04 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-06-12 16:46 [PATCH 4.9 00/31] 4.9.108-stable review Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 01/31] tpm: do not suspend/resume if power stays on Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 02/31] tpm: self test failure should not cause suspend to fail Greg Kroah-Hartman
2018-06-12 16:46   ` Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 03/31] mmap: introduce sane default mmap limits Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 04/31] mmap: relax file size limit for regular files Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 05/31] btrfs: define SUPER_FLAG_METADUMP_V2 Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 07/31] drm: set FMODE_UNSIGNED_OFFSET for drm files Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 08/31] bnx2x: use the right constant Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 09/31] dccp: dont free ccid2_hc_tx_sock struct in dccp_disconnect() Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 10/31] enic: set DMA mask to 47 bit Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 11/31] ip6mr: only set ip6mr_table from setsockopt when ip6mr_new_table succeeds Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 12/31] ipv4: remove warning in ip_recv_error Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 13/31] isdn: eicon: fix a missing-check bug Greg Kroah-Hartman
2018-06-12 16:46 ` Greg Kroah-Hartman [this message]
2018-06-12 16:46 ` [PATCH 4.9 15/31] netdev-FAQ: clarify DaveMs position for stable backports Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 16/31] net/packet: refine check for priv area size Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 18/31] packet: fix reserve calculation Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 19/31] qed: Fix mask for physical address in ILT entry Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 20/31] sctp: not allow transport timeout value less than HZ/5 for hb_timer Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 21/31] team: use netdev_features_t instead of u32 Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 22/31] vhost: synchronize IOTLB message with dev cleanup Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 23/31] vrf: check the original netdevice for generating redirect Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 24/31] net/mlx4: Fix irq-unsafe spinlock usage Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 25/31] rtnetlink: validate attributes in do_setlink() Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 26/31] net: phy: broadcom: Fix bcm_write_exp() Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 27/31] net: metrics: add proper netlink validation Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 28/31] KVM: VMX: Expose SSBD properly to guests, 4.9 supplement Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 29/31] dm bufio: avoid false-positive Wmaybe-uninitialized warning Greg Kroah-Hartman
2018-06-12 16:46 ` [PATCH 4.9 30/31] objtool: Fix gcov check for older versions of GCC Greg Kroah-Hartman
2018-06-12 17:10 ` [PATCH 4.9 00/31] 4.9.108-stable review Nathan Chancellor
2018-06-12 17:45   ` Greg Kroah-Hartman
2018-06-12 20:58 ` Shuah Khan
2018-06-13  4:41   ` Greg Kroah-Hartman
2018-06-13 13:49 ` Guenter Roeck
2018-06-13 14:13 ` Rafael Tinoco
2018-06-13 14:42   ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180612164621.360578922@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=davem@davemloft.net \
    --cc=ktkhai@virtuozzo.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=syzbot+5f1a04e374a635efc426@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.