No description
  • C 96.9%
  • Assembly 0.9%
  • Rust 0.6%
  • Shell 0.6%
  • Python 0.5%
  • Other 0.3%
Find a file
Lorenz Bauer 70b57bf502 bpf, sockmap: Check update requirements after locking
commit 85b8ac01a4 upstream.

It's currently possible to insert sockets in unexpected states into
a sockmap, due to a TOCTTOU when updating the map from a syscall.
sock_map_update_elem checks that sk->sk_state == TCP_ESTABLISHED,
locks the socket and then calls sock_map_update_common. At this
point, the socket may have transitioned into another state, and
the earlier assumptions don't hold anymore. Crucially, it's
conceivable (though very unlikely) that a socket has become unhashed.
This breaks the sockmap's assumption that it will get a callback
via sk->sk_prot->unhash.

Fix this by checking the (fixed) sk_type and sk_protocol without the
lock, followed by a locked check of sk_state.

Unfortunately it's not possible to push the check down into
sock_(map|hash)_update_common, since BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB
run before the socket has transitioned from TCP_SYN_RECV into
TCP_ESTABLISHED.

Fixes: 604326b41a ("bpf, sockmap: convert to generic sk_msg interface")
Signed-off-by: Lorenz Bauer <lmb@cloudflare.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Link: https://lore.kernel.org/bpf/20200207103713.28175-1-lmb@cloudflare.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
History 2020-02-14 16:53:00 -05:00
arch x86/boot: Handle malformed SRAT tables during early ACPI parsing 2020-02-14 16:52:59 -05:00
block compat: scsi: sg: fix v3 compat read/write interface 2020-02-11 04:37:17 -08:00
certs certs: Add wrapper function to check blacklisted binary hash 2019-11-12 12:25:50 +11:00
crypto crypto: api - Fix race condition in crypto_spawn_alg 2020-02-11 04:37:01 -08:00
Documentation PM / devfreq: Add new name attribute for sysfs 2020-02-04 18:18:01 +00:00
drivers iwlwifi: mvm: fix TDLS discovery with the new firmware API 2020-02-14 16:52:58 -05:00
fs NFSv4.0: nfs4_do_fsinfo() should not do implicit lease renewals 2020-02-14 16:52:59 -05:00
include RDMA/uverbs: Verify MR access flags 2020-02-14 16:52:56 -05:00
init Revert "um: Enable CONFIG_CONSTRUCTORS" 2020-02-01 09:33:00 +00:00
ipc ipc/msg.c: consolidate all xxxctl_down() functions 2020-02-11 04:36:39 -08:00
kernel perf/cgroups: Install cgroup events to correct cpuctx 2020-02-11 04:37:28 -08:00
lib lib/test_kasan.c: fix memory leak in kmalloc_oob_krealloc_more() 2020-02-11 04:36:45 -08:00
LICENSES LICENSES: Rename other to deprecated 2019-05-03 06:34:32 -06:00
mm mm/mmu_gather: invalidate TLB correctly on batch allocation failure and flush 2020-02-11 04:37:14 -08:00
net bpf, sockmap: Check update requirements after locking 2020-02-14 16:53:00 -05:00
samples samples/bpf: Reintroduce missed build targets 2020-02-11 04:37:00 -08:00
scripts scripts/find-unused-docs: Fix massive false positives 2020-02-11 04:36:53 -08:00
security broken ping to ipv6 linklocal addresses on debian buster 2020-02-11 04:37:16 -08:00
sound ASoC: Intel: skl_hda_dsp_common: Fix global-out-of-bounds bug 2020-02-11 04:37:21 -08:00
tools selftests/bpf: Test freeing sockmap/sockhash with a socket in it 2020-02-14 16:52:59 -05:00
usr gen_initramfs_list.sh: fix 'bad variable name' error 2020-01-04 00:00:48 +09:00
virt KVM: Play nice with read-only memslots when querying host page size 2020-02-11 04:37:29 -08:00
.clang-format clang-format: Update with the latest for_each macro list 2019-08-31 10:00:51 +02:00
.cocciconfig scripts: add Linux .cocciconfig for coccinelle 2016-07-22 12:13:39 +02:00
.get_maintainer.ignore Opt out of scripts/get_maintainer.pl 2019-05-16 10:53:40 -07:00
.gitattributes .gitattributes: use 'dts' diff driver for dts files 2019-12-04 19:44:11 -08:00
.gitignore modpost: dump missing namespaces into a single modules.nsdeps file 2019-11-11 20:10:01 +09:00
.mailmap MAINTAINERS: update my email address 2020-01-11 14:33:39 -08:00
COPYING COPYING: use the new text with points to the license files 2018-03-23 12:41:45 -06:00
CREDITS Linux 5.4-rc4 2019-10-29 04:43:29 -06:00
Kbuild kbuild: do not descend to ./Kbuild when cleaning 2019-08-21 21:03:58 +09:00
Kconfig docs: kbuild: convert docs to ReST and rename to *.rst 2019-06-14 14:21:21 -06:00
MAINTAINERS MAINTAINERS: correct entries for ISDN/mISDN section 2020-02-11 04:36:38 -08:00
Makefile Linux 5.5.3 2020-02-11 04:37:31 -08:00
README Drop all 00-INDEX files from Documentation/ 2018-09-09 15:08:58 -06:00

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.