From nobody Sat Sep 5 05:49:26 2026 Received: from relay.smtp-ext.broadcom.com (relay.smtp-ext.broadcom.com [192.19.144.207]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF9C5383991; Thu, 3 Sep 2026 00:00:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.19.144.207 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788393647; cv=none; b=G3lX+sVnf9opRaPRn0ae8hTCTqboYRmIKTMmSsshxiC0OvshLqXna9z5dtbVhgrrJpKaPPFphvetcCtUt9DaHm7UOtgIXkIqZf8j+I4xXc3F/VanlfaxJYY7EqP9vEnu6cp6HQAjNb3BpY5WuX72rJ76V86vv9HRAl4KzeSOFws= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788393647; c=relaxed/simple; bh=7Cs2JcBlsUcENEaA5rX9NKfgLDcCYhhpRTVybw4gmzM=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=WU6tFnsHLtDlG9YDN45+DDxsxQ4s35TgJVoqQEazAj1EaiIFJomQ82F7PSLtW4ztTUwyTagVRtQsXgv1DN3SuFR8rjIFkNSBbLjKBnHHR2KU4yCY5fz21ag78F8ahDYc3mKzF20OzjyiyS4ZuGWn/rS7ErvTvSRpK1HHmWoUXoQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com; spf=fail smtp.mailfrom=broadcom.com; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b=U7MGmuec; arc=none smtp.client-ip=192.19.144.207 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=broadcom.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b="U7MGmuec" Received: from mail-lvn-it-01.broadcom.com (mail-lvn-it-01.lvn.broadcom.net [10.36.132.253]) by relay.smtp-ext.broadcom.com (Postfix) with ESMTP id AFD0DC0000F1; Wed, 2 Sep 2026 17:00:36 -0700 (PDT) DKIM-Filter: OpenDKIM Filter v2.11.0 relay.smtp-ext.broadcom.com AFD0DC0000F1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=broadcom.com; s=dkimrelay; t=1788393636; bh=7Cs2JcBlsUcENEaA5rX9NKfgLDcCYhhpRTVybw4gmzM=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=U7MGmuectCQEfbVgwkkXnqi/Q5t0fL4L1PQuycg+9BB5g9RiTFkYTKDHsJZeEXCs7 UpQCFwcGo/HommYpEQz+FsDveFddA+oEmeCToWivj4LvY2Pt6ENnjtoaf7roEQblO2 YpWEmUMlmLaIJgiC0GGNYmn4lL7X+1Pzkf3Y2IRs= Received: from stbirv-lnx-1.igp.broadcom.net (stbirv-lnx-1.igp.broadcom.net [10.67.48.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail-lvn-it-01.broadcom.com (Postfix) with ESMTPSA id 51F6AAA5; Wed, 2 Sep 2026 17:00:36 -0700 (PDT) From: Florian Fainelli To: stable@vger.kernel.org Cc: Eric Dumazet , syzbot+937b5bbb6a815b3e5d0b@syzkaller.appspotmail.com, Kuniyuki Iwashima , Jakub Kicinski , Florian Fainelli , "David S. Miller" , Paolo Abeni , Simon Horman , Neal Cardwell , Matthieu Baerts , Mat Martineau , Geliang Tang , netdev@vger.kernel.org (open list:NETWORKING [GENERAL]), linux-kernel@vger.kernel.org (open list), mptcp@lists.linux.dev (open list:NETWORKING [MPTCP]), bcm-kernel-feedback-list@broadcom.com Subject: [PATCH stable 6.1.y] tcp: fix potential race in tcp_v6_syn_recv_sock() Date: Wed, 2 Sep 2026 17:00:28 -0700 Message-Id: <20260903000029.3508006-3-florian.fainelli@broadcom.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260903000029.3508006-1-florian.fainelli@broadcom.com> References: <20260903000029.3508006-1-florian.fainelli@broadcom.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Eric Dumazet Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Reported-by: syzbot+937b5bbb6a815b3e5d0b@syzkaller.appspotmail.com Closes: https://lore.kernel.org/netdev/69949275.050a0220.2eeac1.0145.GAE@go= ogle.com/ Signed-off-by: Eric Dumazet Reviewed-by: Kuniyuki Iwashima Link: https://patch.msgid.link/20260217161205.2079883-1-edumazet@google.com Signed-off-by: Jakub Kicinski (cherry picked from commit 858d2a4f67ff69e645a43487ef7ea7f28f06deae) [florian: - net/ipv6/tcp_ipv6.c: - Set `newnp->ipv6_fl_list =3D NULL` instead of `newinet->ipv6_fl_list = =3D NULL`, as `ipv6_fl_list` is in `struct ipv6_pinfo`. - Guarded `af_specific` assignment with `#ifdef CONFIG_TCP_MD5SIG` inste= ad of checking `CONFIG_TCP_AO`. - Used `if (tcp_inet6_sk(sk)->repflow)` instead of `inet6_test_bit(REPFL= OW, sk)`.] Assisted-by: Cursor:gemini-3.7-flash Signed-off-by: Florian Fainelli --- include/net/inet_connection_sock.h | 4 +- include/net/tcp.h | 4 +- net/ipv4/syncookies.c | 2 +- net/ipv4/tcp_fastopen.c | 2 +- net/ipv4/tcp_ipv4.c | 8 ++- net/ipv4/tcp_minisocks.c | 2 +- net/ipv6/tcp_ipv6.c | 97 +++++++++++++----------------- net/mptcp/subflow.c | 6 +- net/smc/af_smc.c | 6 +- 9 files changed, 66 insertions(+), 65 deletions(-) diff --git a/include/net/inet_connection_sock.h b/include/net/inet_connecti= on_sock.h index 7649d4901f0c..3d19420dce51 100644 --- a/include/net/inet_connection_sock.h +++ b/include/net/inet_connection_sock.h @@ -42,7 +42,9 @@ struct inet_connection_sock_af_ops { struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req); + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)); u16 net_header_len; u16 net_frag_header_len; u16 sockaddr_len; diff --git a/include/net/tcp.h b/include/net/tcp.h index 9632ac801e01..b54fd01c5bed 100644 --- a/include/net/tcp.h +++ b/include/net/tcp.h @@ -468,7 +468,9 @@ struct sock *tcp_v4_syn_recv_sock(const struct sock *sk= , struct sk_buff *skb, struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req); + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)); int tcp_v4_do_rcv(struct sock *sk, struct sk_buff *skb); int tcp_v4_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len); int tcp_connect(struct sock *sk); diff --git a/net/ipv4/syncookies.c b/net/ipv4/syncookies.c index f9514cf87649..d7202f86566a 100644 --- a/net/ipv4/syncookies.c +++ b/net/ipv4/syncookies.c @@ -199,7 +199,7 @@ struct sock *tcp_get_cookie_sock(struct sock *sk, struc= t sk_buff *skb, bool own_req; =20 child =3D icsk->icsk_af_ops->syn_recv_sock(sk, skb, req, dst, - NULL, &own_req); + NULL, &own_req, NULL); if (child) { refcount_set(&req->rsk_refcnt, 1); tcp_sk(child)->tsoffset =3D tsoff; diff --git a/net/ipv4/tcp_fastopen.c b/net/ipv4/tcp_fastopen.c index cbce1306bb08..c99f10786c1f 100644 --- a/net/ipv4/tcp_fastopen.c +++ b/net/ipv4/tcp_fastopen.c @@ -247,7 +247,7 @@ static struct sock *tcp_fastopen_create_child(struct so= ck *sk, bool own_req; =20 child =3D inet_csk(sk)->icsk_af_ops->syn_recv_sock(sk, skb, req, NULL, - NULL, &own_req); + NULL, &own_req, NULL); if (!child) return NULL; =20 diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c index 753a881ce3cd..ec3b0aa0a626 100644 --- a/net/ipv4/tcp_ipv4.c +++ b/net/ipv4/tcp_ipv4.c @@ -1509,7 +1509,9 @@ struct sock *tcp_v4_syn_recv_sock(const struct sock *= sk, struct sk_buff *skb, struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req) + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)) { struct inet_request_sock *ireq; bool found_dup_sk =3D false; @@ -1565,6 +1567,10 @@ struct sock *tcp_v4_syn_recv_sock(const struct sock = *sk, struct sk_buff *skb, } sk_setup_caps(newsk, dst); =20 +#if IS_ENABLED(CONFIG_IPV6) + if (opt_child_init) + opt_child_init(newsk, sk); +#endif tcp_ca_openreq_child(newsk, dst); =20 tcp_sync_mss(newsk, dst_mtu(dst)); diff --git a/net/ipv4/tcp_minisocks.c b/net/ipv4/tcp_minisocks.c index 22b5748a6ee2..67735100f9ac 100644 --- a/net/ipv4/tcp_minisocks.c +++ b/net/ipv4/tcp_minisocks.c @@ -780,7 +780,7 @@ struct sock *tcp_check_req(struct sock *sk, struct sk_b= uff *skb, * socket is created, wait for troubles. */ child =3D inet_csk(sk)->icsk_af_ops->syn_recv_sock(sk, skb, req, NULL, - req, &own_req); + req, &own_req, NULL); if (!child) goto listen_overflow; =20 diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c index 3d909982d818..d3952b058453 100644 --- a/net/ipv6/tcp_ipv6.c +++ b/net/ipv6/tcp_ipv6.c @@ -1191,11 +1191,48 @@ static void tcp_v6_restore_cb(struct sk_buff *skb) sizeof(struct inet6_skb_parm)); } =20 +/* Called from tcp_v4_syn_recv_sock() for v6_mapped children. */ +static void tcp_v6_mapped_child_init(struct sock *newsk, const struct sock= *sk) +{ + struct inet_sock *newinet =3D inet_sk(newsk); + struct ipv6_pinfo *newnp; + + newinet->pinet6 =3D newnp =3D tcp_inet6_sk(newsk); + + memcpy(newnp, tcp_inet6_sk(sk), sizeof(struct ipv6_pinfo)); + + newnp->saddr =3D newsk->sk_v6_rcv_saddr; + + inet_csk(newsk)->icsk_af_ops =3D &ipv6_mapped; + if (sk_is_mptcp(newsk)) + mptcpv6_handle_mapped(newsk, true); + newsk->sk_backlog_rcv =3D tcp_v4_do_rcv; +#ifdef CONFIG_TCP_MD5SIG + tcp_sk(newsk)->af_specific =3D &tcp_sock_ipv6_mapped_specific; +#endif + + newnp->ipv6_mc_list =3D NULL; + newnp->ipv6_ac_list =3D NULL; + newnp->ipv6_fl_list =3D NULL; + newnp->pktoptions =3D NULL; + newnp->opt =3D NULL; + + /* tcp_v4_syn_recv_sock() has initialized newinet->mc_{index,ttl} */ + newnp->mcast_oif =3D newinet->mc_index; + newnp->mcast_hops =3D newinet->mc_ttl; + + newnp->rcv_flowinfo =3D 0; + if (tcp_inet6_sk(sk)->repflow) + newnp->flow_label =3D 0; +} + static struct sock *tcp_v6_syn_recv_sock(const struct sock *sk, struct sk_= buff *skb, struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req) + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)) { struct inet_request_sock *ireq; struct ipv6_pinfo *newnp; @@ -1211,60 +1248,10 @@ static struct sock *tcp_v6_syn_recv_sock(const stru= ct sock *sk, struct sk_buff * #endif struct flowi6 fl6; =20 - if (skb->protocol =3D=3D htons(ETH_P_IP)) { - /* - * v6 mapped - */ - - newsk =3D tcp_v4_syn_recv_sock(sk, skb, req, dst, - req_unhash, own_req); - - if (!newsk) - return NULL; - - inet_sk(newsk)->pinet6 =3D tcp_inet6_sk(newsk); - - newnp =3D tcp_inet6_sk(newsk); - newtp =3D tcp_sk(newsk); - - memcpy(newnp, np, sizeof(struct ipv6_pinfo)); - - newnp->saddr =3D newsk->sk_v6_rcv_saddr; - - inet_csk(newsk)->icsk_af_ops =3D &ipv6_mapped; - if (sk_is_mptcp(newsk)) - mptcpv6_handle_mapped(newsk, true); - newsk->sk_backlog_rcv =3D tcp_v4_do_rcv; -#ifdef CONFIG_TCP_MD5SIG - newtp->af_specific =3D &tcp_sock_ipv6_mapped_specific; -#endif - - newnp->ipv6_mc_list =3D NULL; - newnp->ipv6_ac_list =3D NULL; - newnp->ipv6_fl_list =3D NULL; - newnp->pktoptions =3D NULL; - newnp->opt =3D NULL; - newnp->mcast_oif =3D inet_iif(skb); - newnp->mcast_hops =3D ip_hdr(skb)->ttl; - newnp->rcv_flowinfo =3D 0; - if (np->repflow) - newnp->flow_label =3D 0; - - /* - * No need to charge this sock to the relevant IPv6 refcnt debug socks c= ount - * here, tcp_create_openreq_child now does this for us, see the comment = in - * that function for the gory details. -acme - */ - - /* It is tricky place. Until this moment IPv4 tcp - worked with IPv6 icsk.icsk_af_ops. - Sync it now. - */ - tcp_sync_mss(newsk, inet_csk(newsk)->icsk_pmtu_cookie); - - return newsk; - } - + if (skb->protocol =3D=3D htons(ETH_P_IP)) + return tcp_v4_syn_recv_sock(sk, skb, req, dst, + req_unhash, own_req, + tcp_v6_mapped_child_init); ireq =3D inet_rsk(req); =20 if (sk_acceptq_is_full(sk)) diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index bdf7f439cf2c..d9734bfb7283 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -699,7 +699,9 @@ static struct sock *subflow_syn_recv_sock(const struct = sock *sk, struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req) + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)) { struct mptcp_subflow_context *listener =3D mptcp_subflow_ctx(sk); struct mptcp_subflow_request_sock *subflow_req; @@ -745,7 +747,7 @@ static struct sock *subflow_syn_recv_sock(const struct = sock *sk, =20 create_child: child =3D listener->icsk_af_ops->syn_recv_sock(sk, skb, req, dst, - req_unhash, own_req); + req_unhash, own_req, opt_child_init); =20 if (child && *own_req) { struct mptcp_subflow_context *ctx =3D mptcp_subflow_ctx(child); diff --git a/net/smc/af_smc.c b/net/smc/af_smc.c index d069e5b156e5..6713296fffd9 100644 --- a/net/smc/af_smc.c +++ b/net/smc/af_smc.c @@ -118,7 +118,9 @@ static struct sock *smc_tcp_syn_recv_sock(const struct = sock *sk, struct request_sock *req, struct dst_entry *dst, struct request_sock *req_unhash, - bool *own_req) + bool *own_req, + void (*opt_child_init)(struct sock *newsk, + const struct sock *sk)) { struct smc_sock *smc; struct sock *child; @@ -143,7 +145,7 @@ static struct sock *smc_tcp_syn_recv_sock(const struct = sock *sk, =20 /* passthrough to original syn recv sock fct */ child =3D smc->ori_af_ops->syn_recv_sock(sk, skb, req, dst, req_unhash, - own_req); + own_req, opt_child_init); /* child must not inherit smc or its ops */ if (child) { rcu_assign_sk_user_data(child, NULL); --=20 2.34.1