Received: by 2002:a05:7412:bb8d:b0:d7:7d3a:4fe2 with SMTP id js13csp28214rdb; Mon, 14 Aug 2023 08:34:40 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFpp/By2kMKvbEFwcDekfHFvi6yw7M7kaupW3hwkz6MuklF2dadh3emk9o2wXezji/Qr4Bu X-Received: by 2002:a17:90a:d489:b0:262:e598:6046 with SMTP id s9-20020a17090ad48900b00262e5986046mr9219860pju.28.1692027280224; Mon, 14 Aug 2023 08:34:40 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1692027280; cv=none; d=google.com; s=arc-20160816; b=AyCFUIVRvXJ13Pw1JShC+WoEx8f6xBZiKeQ/cOFN7j3ytU6sEs4PY+Ehr0Pgq7yyUf aofKZ3ycW1g7AAA/4n+zqyB6hyILGcveHmjwsAcF4VNqzKD7E15wei1IzpalNXoobN5o JwwL3JbnDzx855MhWjkuy55JEHQ2BIJiKF9HC0vn+6u8Om6N+mdmr2+PSiw7J7Xr3uZv MP5yfckLYyHbZdI0ExhDGDy5pmVmGBm38yor6TqymBBeEU6Gjz5RXI5WdlqamfKuh/HV 4bHEn1J5mQ/J1wmLsMMAjeXcZUdJy56Gt6vNkbsbdwuUoBKdbH+HlddAKGEr/MoiuH9h VvOg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:in-reply-to:content-disposition :mime-version:references:message-id:subject:cc:to:from:date; bh=eAc8lbDXIcllkMy0Tb2wKSXViZcxdGeMg8xQVxrh5Io=; fh=0jxTAT5MwFbM+IrPUgyBRhV5fLPeejM2Fh8xGUfkTTE=; b=wweBuPs4qeVqkEORJzB0Pe1rh0WFfGyNyyNNXgCTIs6zF/J2wuxv2prN6f8If95ine g8c7lMuf+W0t4LAgRATmNzL69RRBpOcjLb77UfqbjfGqfS/m5XZjCY0CCHlD3ne+VqwX OBVB6+QPudT5lA00PXXO0bzTomXRuH0RK98ZPbVSc9cnr0JC+XnqcO5wrMdLLc9oDJCp DgTGhT0c3cP+5mAFXtqC0wvXIyTJKa0DL8i2C9vhEsWzlujIJVqN4v0Nmqsn5NdXYgt2 5ninr938x7oMnh7SddKAI8p2CG6KZxvyn+o07pljmphUqTFHCdVU3JF8SL/g04EVHGoV xaJA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id p13-20020a170902e74d00b001b3f6d89579si8424834plf.513.2023.08.14.08.34.27; Mon, 14 Aug 2023 08:34:40 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229551AbjHNONy (ORCPT + 99 others); Mon, 14 Aug 2023 10:13:54 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:39710 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231477AbjHNONT (ORCPT ); Mon, 14 Aug 2023 10:13:19 -0400 Received: from Chamillionaire.breakpoint.cc (Chamillionaire.breakpoint.cc [IPv6:2a0a:51c0:0:237:300::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id BEE11211B; Mon, 14 Aug 2023 07:12:46 -0700 (PDT) Received: from fw by Chamillionaire.breakpoint.cc with local (Exim 4.92) (envelope-from ) id 1qVYJ2-0003LI-EH; Mon, 14 Aug 2023 16:12:28 +0200 Date: Mon, 14 Aug 2023 16:12:28 +0200 From: Florian Westphal To: Dong Chenchen Cc: steffen.klassert@secunet.com, herbert@gondor.apana.org.au, davem@davemloft.net, fw@strlen.de, leon@kernel.org, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, timo.teras@iki.fi, yuehaibing@huawei.com, weiyongjun1@huawei.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [Patch net, v2] net: xfrm: skip policies marked as dead while reinserting policies Message-ID: <20230814141228.GC25551@breakpoint.cc> References: <20230814140013.712001-1-dongchenchen2@huawei.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230814140013.712001-1-dongchenchen2@huawei.com> User-Agent: Mutt/1.10.1 (2018-07-13) X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED, SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Dong Chenchen wrote: > BUG: KASAN: slab-use-after-free in xfrm_policy_inexact_list_reinsert+0xb6/0x430 > Read of size 1 at addr ffff8881051f3bf8 by task ip/668 > > CPU: 2 PID: 668 Comm: ip Not tainted 6.5.0-rc5-00182-g25aa0bebba72-dirty #64 > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13 04/01/2014 > Call Trace: > > dump_stack_lvl+0x72/0xa0 > print_report+0xd0/0x620 > kasan_report+0xb6/0xf0 > xfrm_policy_inexact_list_reinsert+0xb6/0x430 > xfrm_policy_inexact_insert_node.constprop.0+0x537/0x800 > xfrm_policy_inexact_alloc_chain+0x23f/0x320 > xfrm_policy_inexact_insert+0x6b/0x590 > xfrm_policy_insert+0x3b1/0x480 > xfrm_add_policy+0x23c/0x3c0 > xfrm_user_rcv_msg+0x2d0/0x510 > netlink_rcv_skb+0x10d/0x2d0 > xfrm_netlink_rcv+0x49/0x60 > netlink_unicast+0x3fe/0x540 > netlink_sendmsg+0x528/0x970 > sock_sendmsg+0x14a/0x160 > ____sys_sendmsg+0x4fc/0x580 > ___sys_sendmsg+0xef/0x160 > __sys_sendmsg+0xf7/0x1b0 > do_syscall_64+0x3f/0x90 > entry_SYSCALL_64_after_hwframe+0x73/0xdd Thanks for following up. Acked-by: Florian Westphal