From nobody Mon Jun 15 22:02:18 2026 Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BE38D396B98 for ; Tue, 14 Apr 2026 10:49:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776163752; cv=none; b=KCL3p5vSZFW+TPvmSY9KrIvqw44gU1sWdHM6f63yfbOAJ7tOFgVgV+pb99qqm7TKNjFg/QqV+qWtfzXRnNpQ+zA/TMNUqxxHczqGo57uJfgsENmvWaOHh9Hd9f8+ZLKBaL4TnDY7S3rXUsGwaaSrJOrUlIpbOlNkbpjV3jB5gQ8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776163752; c=relaxed/simple; bh=ii6RV1ygzwacH0zsmbOvUdY7N1HLtKusBUxFfTTs880=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gXi1ihApNMxVjSccPJOFAwdRsrnlqLREDPyQbKzT17ChgmCR/AIWxFnjwc6x9ZW7y/QD0SCO/BH/6tW3o0QCsgFp01Fzh9XcDj+aR82BznnSdCf0u9x/p+75sKdDsXQmKpnWxHEClNiM6Q4NQuuJDdKk6WwTGOLLgRZpzUymbpY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=d7iBFd94; arc=none smtp.client-ip=209.85.210.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="d7iBFd94" Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-82ce2e2880cso3522625b3a.0 for ; Tue, 14 Apr 2026 03:49:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1776163749; x=1776768549; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=qdNNcNCom14+hME7vkl9Ojg8yeM3zI8TCPW0A6x3yd0=; b=d7iBFd94OtA2PzD9vTFRILEHBlV/R1ybwhL84mjC1XMApTIkreP5T/mCDAELWdEBFh ZYyT+6f16P3f9qJLrBiFVWYWoL7yjGJXMHV8odKotPllfdbWFhaaxnG82AxqHl6pdD7I pwbMg2zxHyJYtTLKXOqLd8FSNZEhZm2473tPRvG89BLFPva+LOWUdiyZ0Zml/ffoCEcZ aui90YfrvYLQ4UzT//BvGbLS7xzAz3ljGKu5B/J7srUoAHjf0nv2bUkLz6qJh0qauyHt w0XtadPNTh9F10XanRnwVySwUsaanDue4CB5YDbBPGQKPtAX9thEahPs8+fOvsSclxMg rjdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776163749; x=1776768549; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=qdNNcNCom14+hME7vkl9Ojg8yeM3zI8TCPW0A6x3yd0=; b=gDhkY2MFq4PepVwL4VwJ76Iixd6RnQIQiQDDuNZkYSSTrxAYQcWk1YGmDYptSZm838 twC/d3eIde9IInfYdZhEpPmtQChvNxNNA026vrNJTJ/iNrKnjQ9XtZqPV6Um3aXA5ytf 3dRWNsvdQuwlXzlYbl6vPM1e9sDGlsNL/cu71k/iFABTgi1omx267vQv4xykxfjwRrfH /m/9WhU6VX/kVPLSpYe4m77PP8NwbHV19Z3P2ainbkB5fuj+6hKvMOXc9Dt/OaqPMO7W +bVc0O7coRkOZ9MAJ42FZG+xDnHTJ3smCqGglAVkNu3RLQEC3QR8vt8rQTIHFqQ5jtGq DAIg== X-Forwarded-Encrypted: i=1; AFNElJ+QCk4Gm9Waemj2jSWid+p4A5IAGeFT4eUUCt8/d6XrRwOciOeXbjmmFbraKFPSEHzyOu/VXQAJA/4lX8o=@vger.kernel.org X-Gm-Message-State: AOJu0YwpyaTWnowXdGu6wzUGRqlq8XlNO1ydZNdEIjRVLuzT2kXtBvZZ QwQy9qNuCYLWjYPAKu6jm9AALzaenDKJoQ7H/Xh2vGIypiD5EkCMnwmnsW88eSnPnIg3Fw== X-Gm-Gg: AeBDietMO8db+rpQa18WTyYRYnGNO8xIYOC04zIedht6eMn6bwE/XHvpx3NsGOhIDOF OC7/e7L7cl6eaSjkOV1PhMkLTuG9FFjGUXXgbI3GeYdLsRvaTEF5+5ltqGi5jaRJZNpVI1hc9sA M0RqEeXepNp32IyQN52ZPMZEUYLoKaAkdSSquOkIkxRSmPCyasBQ3cgfBocJ36s4skgPoxrqj39 XtvYmRjffxRFt6KXgiaemMHHVQg6o5poxzqw0PjdtNS6ezAmX5DOZ5F703MtGwy42EPR7XFrlF6 7fi6HYKQ0Nl8FcN70OAV6iAtIDl0Qk0xU8vMRvjmIFE9tTWCFsdjgDmK3vlAvahye8ROxMSWT3W nyzAS7LLGDQJmViZ1jXLjTiqcctZ+lYtieIr3nuW7MjlkXzKJwtPloTedxDxuqT+gXGKLihXkDo 6+bJ9fLJWHT3tlbYkX4rq/yfs1hyLc1BZQ X-Received: by 2002:a05:6a00:bd85:b0:82c:9c90:54cf with SMTP id d2e1a72fcca58-82f0c2c3c43mr16170482b3a.43.1776163748735; Tue, 14 Apr 2026 03:49:08 -0700 (PDT) Received: from localhost.localdomain ([180.167.178.215]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-82f0c30ee32sm14570388b3a.7.2026.04.14.03.49.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Apr 2026 03:49:08 -0700 (PDT) From: "Kito Xu (veritas501)" To: pablo@netfilter.org Cc: coreteam@netfilter.org, davem@davemloft.net, edumazet@google.com, ffmancera@riseup.net, fw@strlen.de, horms@kernel.org, hxzene@gmail.com, kuba@kernel.org, linux-kernel@vger.kernel.org, netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, pabeni@redhat.com, phil@nwl.cc Subject: [PATCH v2] netfilter: nfnetlink_osf: fix null-ptr-deref in nf_osf_ttl Date: Tue, 14 Apr 2026 18:49:00 +0800 Message-ID: <20260414104900.2617863-1-hxzene@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260414074556.2512750-1-hxzene@gmail.com> References: <20260414074556.2512750-1-hxzene@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nf_osf_ttl() calls __in_dev_get_rcu(skb->dev) and passes the result to in_dev_for_each_ifa_rcu() without checking for NULL. When the receiving device has no IPv4 configuration (ip_ptr is NULL), __in_dev_get_rcu() returns NULL and in_dev_for_each_ifa_rcu() dereferences it unconditionally, causing a kernel crash. This can happen when a packet arrives on a device that has had its IPv4 configuration removed (e.g., MTU set below IPV4_MIN_MTU causing inetdev_destroy) or on a device that was never assigned an IPv4 address, while an xt_osf or nft_osf rule with TTL_LESS mode is active and the packet TTL exceeds the fingerprint TTL. Add a NULL check for in_dev before using it. When in_dev is NULL, return 0 (no match) since source-address locality cannot be determined without IPv4 addresses on the device. KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:nf_osf_match_one+0x204/0xa70 Call Trace: nf_osf_match+0x2f8/0x780 xt_osf_match_packet+0x11c/0x1f0 ipt_do_table+0x7fe/0x12b0 nf_hook_slow+0xac/0x1e0 ip_rcv+0x123/0x370 __netif_receive_skb_one_core+0x166/0x1b0 process_backlog+0x197/0x590 __napi_poll+0xa1/0x540 net_rx_action+0x401/0xd80 handle_softirqs+0x19f/0x610 Fixes: a218dc82f0b5 ("netfilter: nft_osf: Add ttl option support") Suggested-by: Pablo Neira Ayuso Signed-off-by: Kito Xu (veritas501) Reviewed-by: Fernando Fernandez Mancera Reviewed-by: Florian Westphal --- net/netfilter/nfnetlink_osf.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/net/netfilter/nfnetlink_osf.c b/net/netfilter/nfnetlink_osf.c index d64ce21c7b55..dd2cbbd449e7 100644 --- a/net/netfilter/nfnetlink_osf.c +++ b/net/netfilter/nfnetlink_osf.c @@ -36,6 +36,9 @@ static inline int nf_osf_ttl(const struct sk_buff *skb, const struct in_ifaddr *ifa; int ret =3D 0; =20 + if (!in_dev) + return 0; + if (ttl_check =3D=3D NF_OSF_TTL_TRUE) return ip->ttl =3D=3D f_ttl; if (ttl_check =3D=3D NF_OSF_TTL_NOCHECK) --=20 2.43.0