Received: by 2002:a25:868d:0:0:0:0:0 with SMTP id z13csp2961025ybk; Mon, 18 May 2020 12:09:39 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxRTzh6SyN2E/0Bf5BhKA6pQex8FdB3UEZF5Z8G7SqgKjq6PSNmYwuXSahjX0o/5rXXiT5r X-Received: by 2002:a50:d50f:: with SMTP id u15mr14813458edi.244.1589828979328; Mon, 18 May 2020 12:09:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1589828979; cv=none; d=google.com; s=arc-20160816; b=EbmbBUn4ZTDnJMYKByv7YaKc4Km/ylwR2liI42QGcai2M2yVUy7NU7ItKXg8NxEbwF +8JMmdjD6zfU5f2RyYSDgUhma1n7oYj4+1hZ4xTvGfZZGyNVLF6Ib86fKNNNyNQj4dAA 0qO8UOlVZf41akM3gVS7WSseS4xqTsJNdipkG9eLBhhBwl3OdzqzGEUwTJ8aM1dbgHp2 XxCvrN9/DX2+9ju+bm4FzG7FhqX5LV8B0odVKPmkQHy1g+/rDVsSNVLHuP9331Dpa5Tv yyUdv25N1VsZOadiU/rqy70CnieZH0+Px/8ezhtvhAy3fIvD/PT/y0doBRQliXsiL/Sd 9LqQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=h3yYAIH272e+mlnFkxzwqoz2vVzmryo7zHiBeOYhqOQ=; b=HeOgmAQcncnwH8NKrB4JzdxUJtKLK3USZRG0fSVP+21pe5o0vtiQo0dV2xlrYx8dAu vNJZdr3ggjpXkG7c6ibJr4Em7ZtzeMydjRFb+CaN6XGcW6yKYZelt9zlvT2++LBnxbJC 3yFw8h7pocY6U+OWqH1CMoEITwdCTaK7k5zgGe1O2zjrOf2Y3FWKlkFp7384Ev0WSAMU +IaJdlYqVPdCKk5D+gsBtP6utTlZjM9xoPajrSJiaPMDm7SfaeN9ZxK7yexwUX9aJ8Ah 7LAKAknbX9++ovcWC26gW2LARHlmdx6qvdj5JaPnXAbBNSTEZ+s4WdyW9/yd9xJqsBHB 9Lag== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=sjuPYOiM; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id p4si3295071edd.374.2020.05.18.12.09.15; Mon, 18 May 2020 12:09:39 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=sjuPYOiM; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729505AbgERRnA (ORCPT + 99 others); Mon, 18 May 2020 13:43:00 -0400 Received: from mail.kernel.org ([198.145.29.99]:39890 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728943AbgERRmq (ORCPT ); Mon, 18 May 2020 13:42:46 -0400 Received: from localhost (83-86-89-107.cable.dynamic.v4.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 80FFC20657; Mon, 18 May 2020 17:42:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1589823766; bh=P0lxkl9s3GlC3cewuWXxg05Kz+tb30Ge+n4wF50XGi4=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=sjuPYOiMkAcmdkcz3lvrPdnoY/8Kw1BXTIK8BRtJDPERlQetHym2Mq+ivo1idniLB EWeOoVPbC1Ck2cSG1eha2FjwuZtp45hGhE0kuP1cz7Ltw6m8ceSShLMrQbmpV2r4zz QyUqVQZYupJk2ZCoDrI6O6BY2VF6a05SLoUGt1/M= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Eric Dumazet , syzbot , Cong Wang , "David S. Miller" Subject: [PATCH 4.9 07/90] sch_choke: avoid potential panic in choke_reset() Date: Mon, 18 May 2020 19:35:45 +0200 Message-Id: <20200518173452.682172408@linuxfoundation.org> X-Mailer: git-send-email 2.26.2 In-Reply-To: <20200518173450.930655662@linuxfoundation.org> References: <20200518173450.930655662@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Eric Dumazet [ Upstream commit 8738c85c72b3108c9b9a369a39868ba5f8e10ae0 ] If choke_init() could not allocate q->tab, we would crash later in choke_reset(). BUG: KASAN: null-ptr-deref in memset include/linux/string.h:366 [inline] BUG: KASAN: null-ptr-deref in choke_reset+0x208/0x340 net/sched/sch_choke.c:326 Write of size 8 at addr 0000000000000000 by task syz-executor822/7022 CPU: 1 PID: 7022 Comm: syz-executor822 Not tainted 5.7.0-rc1-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x188/0x20d lib/dump_stack.c:118 __kasan_report.cold+0x5/0x4d mm/kasan/report.c:515 kasan_report+0x33/0x50 mm/kasan/common.c:625 check_memory_region_inline mm/kasan/generic.c:187 [inline] check_memory_region+0x141/0x190 mm/kasan/generic.c:193 memset+0x20/0x40 mm/kasan/common.c:85 memset include/linux/string.h:366 [inline] choke_reset+0x208/0x340 net/sched/sch_choke.c:326 qdisc_reset+0x6b/0x520 net/sched/sch_generic.c:910 dev_deactivate_queue.constprop.0+0x13c/0x240 net/sched/sch_generic.c:1138 netdev_for_each_tx_queue include/linux/netdevice.h:2197 [inline] dev_deactivate_many+0xe2/0xba0 net/sched/sch_generic.c:1195 dev_deactivate+0xf8/0x1c0 net/sched/sch_generic.c:1233 qdisc_graft+0xd25/0x1120 net/sched/sch_api.c:1051 tc_modify_qdisc+0xbab/0x1a00 net/sched/sch_api.c:1670 rtnetlink_rcv_msg+0x44e/0xad0 net/core/rtnetlink.c:5454 netlink_rcv_skb+0x15a/0x410 net/netlink/af_netlink.c:2469 netlink_unicast_kernel net/netlink/af_netlink.c:1303 [inline] netlink_unicast+0x537/0x740 net/netlink/af_netlink.c:1329 netlink_sendmsg+0x882/0xe10 net/netlink/af_netlink.c:1918 sock_sendmsg_nosec net/socket.c:652 [inline] sock_sendmsg+0xcf/0x120 net/socket.c:672 ____sys_sendmsg+0x6bf/0x7e0 net/socket.c:2362 ___sys_sendmsg+0x100/0x170 net/socket.c:2416 __sys_sendmsg+0xec/0x1b0 net/socket.c:2449 do_syscall_64+0xf6/0x7d0 arch/x86/entry/common.c:295 Fixes: 77e62da6e60c ("sch_choke: drop all packets in queue during reset") Signed-off-by: Eric Dumazet Reported-by: syzbot Cc: Cong Wang Signed-off-by: David S. Miller Signed-off-by: Greg Kroah-Hartman --- net/sched/sch_choke.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/net/sched/sch_choke.c +++ b/net/sched/sch_choke.c @@ -382,7 +382,8 @@ static void choke_reset(struct Qdisc *sc sch->q.qlen = 0; sch->qstats.backlog = 0; - memset(q->tab, 0, (q->tab_mask + 1) * sizeof(struct sk_buff *)); + if (q->tab) + memset(q->tab, 0, (q->tab_mask + 1) * sizeof(struct sk_buff *)); q->head = q->tail = 0; red_restart(&q->vars); }