Lorenzo Bianconi
4ebefd396d
net: neigh: fix multiple neigh timer scheduling
[ Upstream commit 071c37983d99da07797294ea78e9da1a6e287144 ]
Neigh timer can be scheduled multiple times from userspace adding
multiple neigh entries and forcing the neigh timer scheduling passing
NTF_USE in the netlink requests.
This will result in a refcount leak and in the following dump stack:
[ 32.465295] NEIGH: BUG, double timer add, state is 8
[ 32.465308] CPU: 0 PID: 416 Comm: double_timer_ad Not tainted 5.2.0+ #65
[ 32.465311] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.12.0-2.fc30 04/01/2014
[ 32.465313] Call Trace:
[ 32.465318] dump_stack+0x7c/0xc0
[ 32.465323] __neigh_event_send+0x20c/0x880
[ 32.465326] ? ___neigh_create+0x846/0xfb0
[ 32.465329] ? neigh_lookup+0x2a9/0x410
[ 32.465332] ? neightbl_fill_info.constprop.0+0x800/0x800
[ 32.465334] neigh_add+0x4f8/0x5e0
[ 32.465337] ? neigh_xmit+0x620/0x620
[ 32.465341] ? find_held_lock+0x85/0xa0
[ 32.465345] rtnetlink_rcv_msg+0x204/0x570
[ 32.465348] ? rtnl_dellink+0x450/0x450
[ 32.465351] ? mark_held_locks+0x90/0x90
[ 32.465354] ? match_held_lock+0x1b/0x230
[ 32.465357] netlink_rcv_skb+0xc4/0x1d0
[ 32.465360] ? rtnl_dellink+0x450/0x450
[ 32.465363] ? netlink_ack+0x420/0x420
[ 32.465366] ? netlink_deliver_tap+0x115/0x560
[ 32.465369] ? __alloc_skb+0xc9/0x2f0
[ 32.465372] netlink_unicast+0x270/0x330
[ 32.465375] ? netlink_attachskb+0x2f0/0x2f0
[ 32.465378] netlink_sendmsg+0x34f/0x5a0
[ 32.465381] ? netlink_unicast+0x330/0x330
[ 32.465385] ? move_addr_to_kernel.part.0+0x20/0x20
[ 32.465388] ? netlink_unicast+0x330/0x330
[ 32.465391] sock_sendmsg+0x91/0xa0
[ 32.465394] ___sys_sendmsg+0x407/0x480
[ 32.465397] ? copy_msghdr_from_user+0x200/0x200
[ 32.465401] ? _raw_spin_unlock_irqrestore+0x37/0x40
[ 32.465404] ? lockdep_hardirqs_on+0x17d/0x250
[ 32.465407] ? __wake_up_common_lock+0xcb/0x110
[ 32.465410] ? __wake_up_common+0x230/0x230
[ 32.465413] ? netlink_bind+0x3e1/0x490
[ 32.465416] ? netlink_setsockopt+0x540/0x540
[ 32.465420] ? __fget_light+0x9c/0xf0
[ 32.465423] ? sockfd_lookup_light+0x8c/0xb0
[ 32.465426] __sys_sendmsg+0xa5/0x110
[ 32.465429] ? __ia32_sys_shutdown+0x30/0x30
[ 32.465432] ? __fd_install+0xe1/0x2c0
[ 32.465435] ? lockdep_hardirqs_off+0xb5/0x100
[ 32.465438] ? mark_held_locks+0x24/0x90
[ 32.465441] ? do_syscall_64+0xf/0x270
[ 32.465444] do_syscall_64+0x63/0x270
[ 32.465448] entry_SYSCALL_64_after_hwframe+0x49/0xbe
Fix the issue unscheduling neigh_timer if selected entry is in 'IN_TIMER'
receiving a netlink request with NTF_USE flag set
Reported-by: Marek Majkowski <marek@cloudflare.com>
Fixes: 0c5c2d3089 ("neigh: Allow for user space users of the neighbour table")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@redhat.com>
Reviewed-by: David Ahern <dsahern@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2019-08-04 09:33:33 +02:00
..
2018-11-10 07:42:58 -08:00
2018-05-16 10:08:41 +02:00
2017-08-11 08:49:32 -07:00
2019-07-10 09:55:42 +02:00
2016-07-12 14:20:18 -07:00
2017-01-15 13:42:54 +01:00
2016-03-18 17:45:08 -04:00
2017-07-05 14:40:14 +02:00
2019-06-11 12:22:49 +02:00
2019-06-11 12:22:47 +02:00
2018-01-31 12:55:57 +01:00
2018-11-23 08:20:34 +01:00
2016-11-23 06:37:09 +01:00
2016-06-07 16:37:14 -07:00
2018-07-25 11:24:00 +02:00
2016-05-25 12:35:09 -07:00
2015-04-02 14:04:59 -04:00
2017-02-04 09:47:11 +01:00
2016-03-14 12:19:46 -04:00
2019-08-04 09:33:33 +02:00
2019-04-17 08:36:46 +02:00
2016-04-26 15:53:05 -04:00
2019-03-13 14:04:52 -07:00
2015-11-22 11:54:10 -05:00
2018-11-13 11:16:51 -08:00
2015-05-31 00:03:21 -07:00
2019-02-27 10:07:01 +01:00
2016-02-17 15:31:27 -05:00
2019-06-11 12:22:46 +02:00
2015-11-03 11:08:22 -05:00
2015-10-05 03:19:06 -07:00
2018-12-17 09:38:31 +01:00
2016-02-08 10:30:42 -05:00
2015-05-25 22:55:37 -04:00
2019-02-23 09:05:59 +01:00
2018-01-17 09:38:53 +01:00
2018-02-13 12:35:57 +01:00
2019-01-26 09:38:34 +01:00
2016-09-28 20:32:38 -04:00
2018-04-13 19:48:06 +02:00
2015-07-09 14:17:15 -07:00
2015-10-26 22:24:22 -07:00
2016-06-29 05:15:14 -04:00