Re: [PATCH net] bonding: fix devconf_all NULL dereference when IPv6 is disabled
From: Hangbin Liu
Date: Tue Jul 07 2026 - 07:42:41 EST
On Tue, Jul 7, 2026 at 9:07 AM <zhangzl2013@xxxxxxx> wrote:
>
> From: Zhaolong Zhang <zhangzl68@xxxxxxxxxxxxxxx>
>
> When booting with the 'ipv6.disable=1' parameter, the devconf_all is
> never initialized because inet6_init() exits before addrconf_init() is
> called which initializes it. bond_send_validate(), however, will still
> call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to
> NULL derefence of net->ipv6.devconf_all in ip6_pol_route().
>
> BUG: kernel NULL pointer dereference, address: 000000000000000c
> [...]
> Workqueue: bond0 bond_arp_monitor [bonding]
> RIP: 0010:ip6_pol_route+0x69/0x480
> [...]
> Call Trace:
> <TASK>
> ? srso_return_thunk+0x5/0x5f
> ? __pfx_ip6_pol_route_output+0x10/0x10
> fib6_rule_lookup+0xfe/0x260
> ? wakeup_preempt+0x8a/0x90
> ? srso_return_thunk+0x5/0x5f
> ? srso_return_thunk+0x5/0x5f
> ? sched_balance_rq+0x369/0x810
> ip6_route_output_flags+0xd7/0x170
> bond_ns_send_all+0xde/0x280 [bonding]
> bond_ab_arp_probe+0x296/0x320 [bonding]
> ? srso_return_thunk+0x5/0x5f
> bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]
> process_one_work+0x196/0x370
> worker_thread+0x1af/0x320
> ? srso_return_thunk+0x5/0x5f
> ? __pfx_worker_thread+0x10/0x10
> kthread+0xe3/0x120
> ? __pfx_kthread+0x10/0x10
> ret_from_fork+0x199/0x260
> ? __pfx_kthread+0x10/0x10
> ret_from_fork_asm+0x1a/0x30
> </TASK>
>
> Fix this by adding ipv6_mod_enabled() condition check in the caller.
>
> Fixes: 4e24be018eb9 ("bonding: add new parameter ns_targets")
> Signed-off-by: Qianheng Peng <pengqh1@xxxxxxxxxxxxxxx>
> Signed-off-by: Zhaolong Zhang <zhangzl68@xxxxxxxxxxxxxxx>
> ---
> drivers/net/bonding/bond_main.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
> index e044fc733b8c..522eab060f9e 100644
> --- a/drivers/net/bonding/bond_main.c
> +++ b/drivers/net/bonding/bond_main.c
> @@ -3455,7 +3455,8 @@ static void bond_send_validate(struct bonding *bond, struct slave *slave)
> {
> bond_arp_send_all(bond, slave);
> #if IS_ENABLED(CONFIG_IPV6)
> - bond_ns_send_all(bond, slave);
> + if (likely(ipv6_mod_enabled()))
> + bond_ns_send_all(bond, slave);
> #endif
> }
>
Thanks for your fix. Next time please use PATCHv2 with a change log.
Reviewed-by: Hangbin Liu <liuhangbin@xxxxxxxxx>