Re: [Patch net, v2] net: xfrm: skip policies marked as dead while reinserting policies

From: Florian Westphal
Date: Mon Aug 14 2023 - 10:14:24 EST


Dong Chenchen <dongchenchen2@xxxxxxxxxx> wrote:
> BUG: KASAN: slab-use-after-free in xfrm_policy_inexact_list_reinsert+0xb6/0x430
> Read of size 1 at addr ffff8881051f3bf8 by task ip/668
>
> CPU: 2 PID: 668 Comm: ip Not tainted 6.5.0-rc5-00182-g25aa0bebba72-dirty #64
> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13 04/01/2014
> Call Trace:
> <TASK>
> dump_stack_lvl+0x72/0xa0
> print_report+0xd0/0x620
> kasan_report+0xb6/0xf0
> xfrm_policy_inexact_list_reinsert+0xb6/0x430
> xfrm_policy_inexact_insert_node.constprop.0+0x537/0x800
> xfrm_policy_inexact_alloc_chain+0x23f/0x320
> xfrm_policy_inexact_insert+0x6b/0x590
> xfrm_policy_insert+0x3b1/0x480
> xfrm_add_policy+0x23c/0x3c0
> xfrm_user_rcv_msg+0x2d0/0x510
> netlink_rcv_skb+0x10d/0x2d0
> xfrm_netlink_rcv+0x49/0x60
> netlink_unicast+0x3fe/0x540
> netlink_sendmsg+0x528/0x970
> sock_sendmsg+0x14a/0x160
> ____sys_sendmsg+0x4fc/0x580
> ___sys_sendmsg+0xef/0x160
> __sys_sendmsg+0xf7/0x1b0
> do_syscall_64+0x3f/0x90
> entry_SYSCALL_64_after_hwframe+0x73/0xdd

Thanks for following up.

Acked-by: Florian Westphal <fw@xxxxxxxxx>