Re: [PATCH net 1/1] net: use random salt for netdev name hash to prevent text base leak

From: Eric Dumazet

Date: Fri Oct 02 2026 - 04:23:20 EST


On Fri, Oct 2, 2026 at 8:52 AM Zhengchuan Liang <zcliangcn@xxxxxxxxx> wrote:
>
> dev_name_hash() uses the network namespace pointer as the salt for the
> network device name hash table. Unprivileged users can use SIOCGIFINDEX
> to look up attacker-chosen nonexistent names. Timing these lookups
> reveals which names share a bucket with an existing name, allowing the
> salt to be recovered. For init_net, recovering the salt reveals the
> kernel text base and defeats KASLR.
>
> Use the per-network namespace random value from net_hash_mix() as the
> salt instead. The value remains stable for the lifetime of the namespace.
> Since all name insertions and lookups use dev_name_hash(), this only
> changes bucket placement.
>
> Fixes: 8387ff2577eb ("vfs: make the string hashes salt the hash")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <zcliangcn@xxxxxxxxx>
> ---
> net/core/dev.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
> diff --git a/net/core/dev.c b/net/core/dev.c
> index 18dc88990510..f3eca7fa2481 100644
> --- a/net/core/dev.c
> +++ b/net/core/dev.c
> @@ -98,6 +98,7 @@
> #include <linux/bpf.h>
> #include <linux/bpf_trace.h>
> #include <net/net_namespace.h>
> +#include <net/netns/hash.h>
> #include <net/sock.h>
> #include <net/busy_poll.h>
> #include <linux/rtnetlink.h>
> @@ -193,7 +194,10 @@ static inline void dev_base_seq_inc(struct net *net)
>
> static inline struct hlist_head *dev_name_hash(struct net *net, const char *name)
> {
> - unsigned int hash = full_name_hash(net, name, strnlen(name, IFNAMSIZ));
> + unsigned long salt = net_hash_mix(net);
> + unsigned int hash;
> +
> + hash = full_name_hash((void *)salt, name, strnlen(name, IFNAMSIZ));
>
> return &net->dev_name_head[hash_32(hash, NETDEV_HASHBITS)];

Thanks for your patch.

CC Linus.

It seems this patch should target net-next, local KASLR attacks are
not a serious concern.

Your patch would allow an attacker to disclose net_hash_mix.
Leaking net->hash_mix compromises other per-netns hash tables.

u32 hash_mix is too weak for full_name_hash()

1) What about passing NULL salt instead?

net->dev_name_head is already a per-netns hash table,
and only CAP_NET_ADMIN inside that netns can add/rename devices in it.

2) I thought about widening net->hash_mix to unsigned long (get_random_long())
(but not change net_hash_mix() u32 return type to avoid side effects)

But full_name_hash() skips HASH_MIX for len < 8, any 64-bit salt passed to
full_name_hash() can be recovered quite easily.

pw-bot: cr