Jiri Slaby c5b460
From: Eric Dumazet <edumazet@google.com>
Jiri Slaby c5b460
Date: Tue, 16 May 2023 14:23:42 +0000
Jiri Slaby c5b460
Subject: [PATCH] vlan: fix a potential uninit-value in
Jiri Slaby c5b460
 vlan_dev_hard_start_xmit()
Jiri Slaby c5b460
References: bsc#1012628
Jiri Slaby c5b460
Patch-mainline: 6.3.4
Jiri Slaby c5b460
Git-commit: dacab578c7c6cd06c50c89dfa36b0e0f10decd4e
Jiri Slaby c5b460
Jiri Slaby c5b460
[ Upstream commit dacab578c7c6cd06c50c89dfa36b0e0f10decd4e ]
Jiri Slaby c5b460
Jiri Slaby c5b460
syzbot triggered the following splat [1], sending an empty message
Jiri Slaby c5b460
through pppoe_sendmsg().
Jiri Slaby c5b460
Jiri Slaby c5b460
When VLAN_FLAG_REORDER_HDR flag is set, vlan_dev_hard_header()
Jiri Slaby c5b460
does not push extra bytes for the VLAN header, because vlan is offloaded.
Jiri Slaby c5b460
Jiri Slaby c5b460
Unfortunately vlan_dev_hard_start_xmit() first reads veth->h_vlan_proto
Jiri Slaby c5b460
before testing (vlan->flags & VLAN_FLAG_REORDER_HDR).
Jiri Slaby c5b460
Jiri Slaby c5b460
We need to swap the two conditions.
Jiri Slaby c5b460
Jiri Slaby c5b460
[1]
Jiri Slaby c5b460
BUG: KMSAN: uninit-value in vlan_dev_hard_start_xmit+0x171/0x7f0 net/8021q/vlan_dev.c:111
Jiri Slaby c5b460
vlan_dev_hard_start_xmit+0x171/0x7f0 net/8021q/vlan_dev.c:111
Jiri Slaby c5b460
__netdev_start_xmit include/linux/netdevice.h:4883 [inline]
Jiri Slaby c5b460
netdev_start_xmit include/linux/netdevice.h:4897 [inline]
Jiri Slaby c5b460
xmit_one net/core/dev.c:3580 [inline]
Jiri Slaby c5b460
dev_hard_start_xmit+0x253/0xa20 net/core/dev.c:3596
Jiri Slaby c5b460
__dev_queue_xmit+0x3c7f/0x5ac0 net/core/dev.c:4246
Jiri Slaby c5b460
dev_queue_xmit include/linux/netdevice.h:3053 [inline]
Jiri Slaby c5b460
pppoe_sendmsg+0xa93/0xb80 drivers/net/ppp/pppoe.c:900
Jiri Slaby c5b460
sock_sendmsg_nosec net/socket.c:724 [inline]
Jiri Slaby c5b460
sock_sendmsg net/socket.c:747 [inline]
Jiri Slaby c5b460
____sys_sendmsg+0xa24/0xe40 net/socket.c:2501
Jiri Slaby c5b460
___sys_sendmsg+0x2a1/0x3f0 net/socket.c:2555
Jiri Slaby c5b460
__sys_sendmmsg+0x411/0xa50 net/socket.c:2641
Jiri Slaby c5b460
__do_sys_sendmmsg net/socket.c:2670 [inline]
Jiri Slaby c5b460
__se_sys_sendmmsg net/socket.c:2667 [inline]
Jiri Slaby c5b460
__x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2667
Jiri Slaby c5b460
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
Jiri Slaby c5b460
do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
Jiri Slaby c5b460
entry_SYSCALL_64_after_hwframe+0x63/0xcd
Jiri Slaby c5b460
Jiri Slaby c5b460
Uninit was created at:
Jiri Slaby c5b460
slab_post_alloc_hook+0x12d/0xb60 mm/slab.h:774
Jiri Slaby c5b460
slab_alloc_node mm/slub.c:3452 [inline]
Jiri Slaby c5b460
kmem_cache_alloc_node+0x543/0xab0 mm/slub.c:3497
Jiri Slaby c5b460
kmalloc_reserve+0x148/0x470 net/core/skbuff.c:520
Jiri Slaby c5b460
__alloc_skb+0x3a7/0x850 net/core/skbuff.c:606
Jiri Slaby c5b460
alloc_skb include/linux/skbuff.h:1277 [inline]
Jiri Slaby c5b460
sock_wmalloc+0xfe/0x1a0 net/core/sock.c:2583
Jiri Slaby c5b460
pppoe_sendmsg+0x3af/0xb80 drivers/net/ppp/pppoe.c:867
Jiri Slaby c5b460
sock_sendmsg_nosec net/socket.c:724 [inline]
Jiri Slaby c5b460
sock_sendmsg net/socket.c:747 [inline]
Jiri Slaby c5b460
____sys_sendmsg+0xa24/0xe40 net/socket.c:2501
Jiri Slaby c5b460
___sys_sendmsg+0x2a1/0x3f0 net/socket.c:2555
Jiri Slaby c5b460
__sys_sendmmsg+0x411/0xa50 net/socket.c:2641
Jiri Slaby c5b460
__do_sys_sendmmsg net/socket.c:2670 [inline]
Jiri Slaby c5b460
__se_sys_sendmmsg net/socket.c:2667 [inline]
Jiri Slaby c5b460
__x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2667
Jiri Slaby c5b460
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
Jiri Slaby c5b460
do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
Jiri Slaby c5b460
entry_SYSCALL_64_after_hwframe+0x63/0xcd
Jiri Slaby c5b460
Jiri Slaby c5b460
CPU: 0 PID: 29770 Comm: syz-executor.0 Not tainted 6.3.0-rc6-syzkaller-gc478e5b17829 #0
Jiri Slaby c5b460
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023
Jiri Slaby c5b460
Jiri Slaby c5b460
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Jiri Slaby c5b460
Reported-by: syzbot <syzkaller@googlegroups.com>
Jiri Slaby c5b460
Signed-off-by: Eric Dumazet <edumazet@google.com>
Jiri Slaby c5b460
Signed-off-by: David S. Miller <davem@davemloft.net>
Jiri Slaby c5b460
Signed-off-by: Sasha Levin <sashal@kernel.org>
Jiri Slaby c5b460
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Jiri Slaby c5b460
---
Jiri Slaby c5b460
 net/8021q/vlan_dev.c | 4 ++--
Jiri Slaby c5b460
 1 file changed, 2 insertions(+), 2 deletions(-)
Jiri Slaby c5b460
Jiri Slaby c5b460
diff --git a/net/8021q/vlan_dev.c b/net/8021q/vlan_dev.c
Jiri Slaby c5b460
index 5920544e..0fa52bcc 100644
Jiri Slaby c5b460
--- a/net/8021q/vlan_dev.c
Jiri Slaby c5b460
+++ b/net/8021q/vlan_dev.c
Jiri Slaby c5b460
@@ -108,8 +108,8 @@ static netdev_tx_t vlan_dev_hard_start_xmit(struct sk_buff *skb,
Jiri Slaby c5b460
 	 * NOTE: THIS ASSUMES DIX ETHERNET, SPECIFICALLY NOT SUPPORTING
Jiri Slaby c5b460
 	 * OTHER THINGS LIKE FDDI/TokenRing/802.3 SNAPs...
Jiri Slaby c5b460
 	 */
Jiri Slaby c5b460
-	if (veth->h_vlan_proto != vlan->vlan_proto ||
Jiri Slaby c5b460
-	    vlan->flags & VLAN_FLAG_REORDER_HDR) {
Jiri Slaby c5b460
+	if (vlan->flags & VLAN_FLAG_REORDER_HDR ||
Jiri Slaby c5b460
+	    veth->h_vlan_proto != vlan->vlan_proto) {
Jiri Slaby c5b460
 		u16 vlan_tci;
Jiri Slaby c5b460
 		vlan_tci = vlan->vlan_id;
Jiri Slaby c5b460
 		vlan_tci |= vlan_dev_get_egress_qos_mask(dev, skb->priority);
Jiri Slaby c5b460
-- 
Jiri Slaby c5b460
2.35.3
Jiri Slaby c5b460