Commit d5cd9244 authored by Eric W. Biederman's avatar Eric W. Biederman Committed by David S. Miller

macvlan: Fix use after free of struct macvlan_port.

When the macvlan driver was extended to call unregisgter_netdevice_queue
in 23289a37, a use after free of struct
macvlan_port was introduced.  The code in dellink relied on unregister_netdevice
actually unregistering the net device so it would be safe to free macvlan_port.

Since unregister_netdevice_queue can just queue up the unregister instead of
performing the unregiser immediately we free the macvlan_port too soon and
then the code in macvlan_stop removes the macaddress for the set of macaddress
to listen for and uses memory that has already been freed.

To fix this add a reference count to track when it is safe to free the macvlan_port
and move the call of macvlan_port_destroy into macvlan_uninit which is guaranteed
to be called after the final macvlan_port_close.
Signed-off-by: default avatarEric W. Biederman <ebiederm@aristanetworks.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent ac0a121d
...@@ -39,8 +39,11 @@ struct macvlan_port { ...@@ -39,8 +39,11 @@ struct macvlan_port {
struct list_head vlans; struct list_head vlans;
struct rcu_head rcu; struct rcu_head rcu;
bool passthru; bool passthru;
int count;
}; };
static void macvlan_port_destroy(struct net_device *dev);
#define macvlan_port_get_rcu(dev) \ #define macvlan_port_get_rcu(dev) \
((struct macvlan_port *) rcu_dereference(dev->rx_handler_data)) ((struct macvlan_port *) rcu_dereference(dev->rx_handler_data))
#define macvlan_port_get(dev) ((struct macvlan_port *) dev->rx_handler_data) #define macvlan_port_get(dev) ((struct macvlan_port *) dev->rx_handler_data)
...@@ -457,8 +460,13 @@ static int macvlan_init(struct net_device *dev) ...@@ -457,8 +460,13 @@ static int macvlan_init(struct net_device *dev)
static void macvlan_uninit(struct net_device *dev) static void macvlan_uninit(struct net_device *dev)
{ {
struct macvlan_dev *vlan = netdev_priv(dev); struct macvlan_dev *vlan = netdev_priv(dev);
struct macvlan_port *port = vlan->port;
free_percpu(vlan->pcpu_stats); free_percpu(vlan->pcpu_stats);
port->count -= 1;
if (!port->count)
macvlan_port_destroy(port->dev);
} }
static struct rtnl_link_stats64 *macvlan_dev_get_stats64(struct net_device *dev, static struct rtnl_link_stats64 *macvlan_dev_get_stats64(struct net_device *dev,
...@@ -691,12 +699,13 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev, ...@@ -691,12 +699,13 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev,
vlan->mode = nla_get_u32(data[IFLA_MACVLAN_MODE]); vlan->mode = nla_get_u32(data[IFLA_MACVLAN_MODE]);
if (vlan->mode == MACVLAN_MODE_PASSTHRU) { if (vlan->mode == MACVLAN_MODE_PASSTHRU) {
if (!list_empty(&port->vlans)) if (port->count)
return -EINVAL; return -EINVAL;
port->passthru = true; port->passthru = true;
memcpy(dev->dev_addr, lowerdev->dev_addr, ETH_ALEN); memcpy(dev->dev_addr, lowerdev->dev_addr, ETH_ALEN);
} }
port->count += 1;
err = register_netdevice(dev); err = register_netdevice(dev);
if (err < 0) if (err < 0)
goto destroy_port; goto destroy_port;
...@@ -707,7 +716,8 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev, ...@@ -707,7 +716,8 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev,
return 0; return 0;
destroy_port: destroy_port:
if (list_empty(&port->vlans)) port->count -= 1;
if (!port->count)
macvlan_port_destroy(lowerdev); macvlan_port_destroy(lowerdev);
return err; return err;
...@@ -725,13 +735,9 @@ static int macvlan_newlink(struct net *src_net, struct net_device *dev, ...@@ -725,13 +735,9 @@ static int macvlan_newlink(struct net *src_net, struct net_device *dev,
void macvlan_dellink(struct net_device *dev, struct list_head *head) void macvlan_dellink(struct net_device *dev, struct list_head *head)
{ {
struct macvlan_dev *vlan = netdev_priv(dev); struct macvlan_dev *vlan = netdev_priv(dev);
struct macvlan_port *port = vlan->port;
list_del(&vlan->list); list_del(&vlan->list);
unregister_netdevice_queue(dev, head); unregister_netdevice_queue(dev, head);
if (list_empty(&port->vlans))
macvlan_port_destroy(port->dev);
} }
EXPORT_SYMBOL_GPL(macvlan_dellink); EXPORT_SYMBOL_GPL(macvlan_dellink);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment