Re: [PATCH net] bonding: fix devconf_all NULL dereference when IPv6 is disabled

From: Hangbin Liu

Date: Tue Jul 07 2026 - 07:41:45 EST


On Tue, Jul 7, 2026 at 6:35 PM Vadim Fedorenko
<vadim.fedorenko@xxxxxxxxx> wrote:
>
> On 07/07/2026 02:06, zhangzl2013@xxxxxxx wrote:
> > From: Zhaolong Zhang <zhangzl68@xxxxxxxxxxxxxxx>
> >
> > When booting with the 'ipv6.disable=1' parameter, the devconf_all is
> > never initialized because inet6_init() exits before addrconf_init() is
> > called which initializes it. bond_send_validate(), however, will still
> > call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to
> > NULL derefence of net->ipv6.devconf_all in ip6_pol_route().
> >
> > BUG: kernel NULL pointer dereference, address: 000000000000000c
> > [...]
> > Workqueue: bond0 bond_arp_monitor [bonding]
> > RIP: 0010:ip6_pol_route+0x69/0x480
> > [...]
> > Call Trace:
> > <TASK>
> > ? srso_return_thunk+0x5/0x5f
> > ? __pfx_ip6_pol_route_output+0x10/0x10
> > fib6_rule_lookup+0xfe/0x260
> > ? wakeup_preempt+0x8a/0x90
> > ? srso_return_thunk+0x5/0x5f
> > ? srso_return_thunk+0x5/0x5f
> > ? sched_balance_rq+0x369/0x810
> > ip6_route_output_flags+0xd7/0x170
> > bond_ns_send_all+0xde/0x280 [bonding]
> > bond_ab_arp_probe+0x296/0x320 [bonding]
> > ? srso_return_thunk+0x5/0x5f
> > bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]
> > process_one_work+0x196/0x370
> > worker_thread+0x1af/0x320
> > ? srso_return_thunk+0x5/0x5f
> > ? __pfx_worker_thread+0x10/0x10
> > kthread+0xe3/0x120
> > ? __pfx_kthread+0x10/0x10
> > ret_from_fork+0x199/0x260
> > ? __pfx_kthread+0x10/0x10
> > ret_from_fork_asm+0x1a/0x30
> > </TASK>
> >
> > Fix this by adding ipv6_mod_enabled() condition check in the caller.
> >
> > Fixes: 4e24be018eb9 ("bonding: add new parameter ns_targets")
> > Signed-off-by: Qianheng Peng <pengqh1@xxxxxxxxxxxxxxx>
> > Signed-off-by: Zhaolong Zhang <zhangzl68@xxxxxxxxxxxxxxx>
> > ---
> > drivers/net/bonding/bond_main.c | 3 ++-
> > 1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
> > index e044fc733b8c..522eab060f9e 100644
> > --- a/drivers/net/bonding/bond_main.c
> > +++ b/drivers/net/bonding/bond_main.c
> > @@ -3455,7 +3455,8 @@ static void bond_send_validate(struct bonding *bond, struct slave *slave)
> > {
> > bond_arp_send_all(bond, slave);
> > #if IS_ENABLED(CONFIG_IPV6)
> > - bond_ns_send_all(bond, slave);
> > + if (likely(ipv6_mod_enabled()))
> > + bond_ns_send_all(bond, slave);
> > #endif
> > }
> >
>
> ipv6_mod_enabled() doesn't depend on CONFIG_IPV6, please, remove
> #if IS_ENABLED as well


No, bond_ns_send_all() is static and protected by IS_ENABLED(CONFIG_IPV6).
Remove this IS_ENABLED will cause build error.

Thanks
Hangbin