Skip to content

Commit b09e6cc

Browse files
ummakynesgregkh
authored andcommitted
netfilter: nf_tables: double hook unregistration in netns path
commit f9a4300 upstream. __nft_release_hooks() is called from pre_netns exit path which unregisters the hooks, then the NETDEV_UNREGISTER event is triggered which unregisters the hooks again. [ 565.221461] WARNING: CPU: 18 PID: 193 at net/netfilter/core.c:495 __nf_unregister_net_hook+0x247/0x270 [...] [ 565.246890] CPU: 18 PID: 193 Comm: kworker/u64:1 Tainted: G E 5.18.0-rc7+ #27 [ 565.253682] Workqueue: netns cleanup_net [ 565.257059] RIP: 0010:__nf_unregister_net_hook+0x247/0x270 [...] [ 565.297120] Call Trace: [ 565.300900] <TASK> [ 565.304683] nf_tables_flowtable_event+0x16a/0x220 [nf_tables] [ 565.308518] raw_notifier_call_chain+0x63/0x80 [ 565.312386] unregister_netdevice_many+0x54f/0xb50 Unregister and destroy netdev hook from netns pre_exit via kfree_rcu so the NETDEV_UNREGISTER path see unregistered hooks. Fixes: 767d121 ("netfilter: nftables: fix possible UAF over chains from packet path in netns") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent b05a24c commit b09e6cc

File tree

2 files changed

+30
-7
lines changed

2 files changed

+30
-7
lines changed

net/netfilter/nf_tables_api.c

Lines changed: 27 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -219,9 +219,10 @@ static int nf_tables_register_hook(struct net *net,
219219
return nf_register_net_hook(net, ops);
220220
}
221221

222-
static void nf_tables_unregister_hook(struct net *net,
223-
const struct nft_table *table,
224-
struct nft_chain *chain)
222+
static void __nf_tables_unregister_hook(struct net *net,
223+
const struct nft_table *table,
224+
struct nft_chain *chain,
225+
bool release_netdev)
225226
{
226227
const struct nft_base_chain *basechain;
227228
const struct nf_hook_ops *ops;
@@ -236,6 +237,16 @@ static void nf_tables_unregister_hook(struct net *net,
236237
return basechain->type->ops_unregister(net, ops);
237238

238239
nf_unregister_net_hook(net, ops);
240+
if (release_netdev &&
241+
table->family == NFPROTO_NETDEV)
242+
nft_base_chain(chain)->ops.dev = NULL;
243+
}
244+
245+
static void nf_tables_unregister_hook(struct net *net,
246+
const struct nft_table *table,
247+
struct nft_chain *chain)
248+
{
249+
__nf_tables_unregister_hook(net, table, chain, false);
239250
}
240251

241252
static int nft_trans_table_add(struct nft_ctx *ctx, int msg_type)
@@ -5997,8 +6008,9 @@ nft_flowtable_type_get(struct net *net, u8 family)
59976008
return ERR_PTR(-ENOENT);
59986009
}
59996010

6000-
static void nft_unregister_flowtable_net_hooks(struct net *net,
6001-
struct nft_flowtable *flowtable)
6011+
static void __nft_unregister_flowtable_net_hooks(struct net *net,
6012+
struct nft_flowtable *flowtable,
6013+
bool release_netdev)
60026014
{
60036015
int i;
60046016

@@ -6007,9 +6019,17 @@ static void nft_unregister_flowtable_net_hooks(struct net *net,
60076019
continue;
60086020

60096021
nf_unregister_net_hook(net, &flowtable->ops[i]);
6022+
if (release_netdev)
6023+
flowtable->ops[i].dev = NULL;
60106024
}
60116025
}
60126026

6027+
static void nft_unregister_flowtable_net_hooks(struct net *net,
6028+
struct nft_flowtable *flowtable)
6029+
{
6030+
__nft_unregister_flowtable_net_hooks(net, flowtable, false);
6031+
}
6032+
60136033
static int nf_tables_newflowtable(struct net *net, struct sock *nlsk,
60146034
struct sk_buff *skb,
60156035
const struct nlmsghdr *nlh,
@@ -8192,9 +8212,9 @@ static void __nft_release_hook(struct net *net, struct nft_table *table)
81928212
struct nft_chain *chain;
81938213

81948214
list_for_each_entry(chain, &table->chains, list)
8195-
nf_tables_unregister_hook(net, table, chain);
8215+
__nf_tables_unregister_hook(net, table, chain, true);
81968216
list_for_each_entry(flowtable, &table->flowtables, list)
8197-
nft_unregister_flowtable_net_hooks(net, flowtable);
8217+
__nft_unregister_flowtable_net_hooks(net, flowtable, true);
81988218
}
81998219

82008220
static void __nft_release_hooks(struct net *net)

net/netfilter/nft_chain_filter.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -296,6 +296,9 @@ static void nft_netdev_event(unsigned long event, struct net_device *dev,
296296
if (strcmp(basechain->dev_name, dev->name) != 0)
297297
return;
298298

299+
if (!basechain->ops.dev)
300+
return;
301+
299302
/* UNREGISTER events are also happpening on netns exit.
300303
*
301304
* Altough nf_tables core releases all tables/chains, only

0 commit comments

Comments
 (0)