From nobody Sat Sep 26 22:01:47 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7F1FF2BE051 for ; Sat, 29 Aug 2026 03:01:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787972494; cv=none; b=AqYmViWvOoOyZDy4vMaLKfVaNduS6v13LyvvQabmqJIzded5542vF01Ywo//jTWO1zvb6BjKQtcwaoV7qaAYHhUzbjiQMPafu2nbZhWUVo5Gw0m1kIR/T1CJyzkgwAv16oOXKwJsNdVQGD+zw91co4+k0hZz5Ik5FFgCp7Vya/M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787972494; c=relaxed/simple; bh=qQdMi8Jgb8bfEkmTNXvPHUJmLQKYjK/Vxzq0/r/+LkE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DVn4EpoiG+xhERiQlEYMCmSzH0bbViNxz1ge/6L0uCMxx8yoBF+7xZaLNB3BAnnDLBPCaQMlpFHZMVAw3yyvaiVKK63iL7w0p1oHj0eunXaFEpxP145Lmy415zWGDV/T+UDgV7NR8tT2UOcoycBqYTIevW3KSWnwaYYfTeLHpH8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O367jAo4; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O367jAo4" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-495590dde14so15119425e9.0 for ; Fri, 28 Aug 2026 20:01:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787972491; x=1788577291; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5EH4v06YGJpqqsWC3cck6VVt8t8Ztw0dDHt3qG/Q8H0=; b=O367jAo4IPDUqyw7wcAEErND/dFeWT5ZXlWhry/Vn656CCCYZBiQ3kezXjgF7CFh6u wBPOXu3mTHk7iQ9Y9qUgEQxf5kpDrK1kQ1M3y8XoY/tfu2ULwFaZSYUbBUsEsJb9tjmY OPNxPzdTo9aFbCTwH7o/w8VvIXetuCVoOv9HrnIpvHAwUod+LFDsLDZKJaYPx+bNRCqf wol1s3XZxWPJGW7of1CPUQLF/7TxuqwZLFVdWfVDiy9zl3i3Ycragz5nhF1o5UsVISox CH5PVIZribqDeH8hqlqE8068mzkAexKyT5djqInAHfzhl3ieSo9Yp5f5ehAPcZ3U3adZ vQWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787972491; x=1788577291; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5EH4v06YGJpqqsWC3cck6VVt8t8Ztw0dDHt3qG/Q8H0=; b=av9586uqnKHvYqcr0G9Y4LZmV10ZICbi0tmJBi29MKwiXgywvPU670MKJWrS4cQR4z M68Bxr08eXm8PdPY+nLbo5/8WwqlvQxn2u8B9ocUukzg1lZCy5Sigel9WN+BzfTUKoEq UjjSAIhy4ZvEeVzFcRKRnNccJmIU8JD0R6o58UlSNNQTHixxpPeFUsAiDm7C1ihsLcbq ErXDcwl1O+SFqMUojA854xGIoUjrXCJiSgzWz5Au+debSFwZUoPsJQ6D0W42l89PnRuH sVB5uwPf1Ue3h7nM+GACUKrpHa2AQXQhCafiqBFw2m40jpRmrv+oMOJREBEAVFwDxP/a S/9w== X-Forwarded-Encrypted: i=1; AHgh+RqzibVycmSjTXw4w4wX5NChQtyy/2T3CzcSMv0z/oOkcSi5N5vTK7iTO/+ms5M5BaSPARCtBRFfOVhep7I=@vger.kernel.org X-Gm-Message-State: AFuF++l+61ICZhYbbEEwdn/TMorzpdpyrOZ4GWjgrkZPMcsEDrjgJNo4 bBQkL4O+9QAqILrRThYRq/LFEFyCnL+W3WRm94fcGfh/8QbOCoJsup5t X-Gm-Gg: AR+sD11F5q8UzbssvU/QVXNdpbTYzvS8tfG93Y5l2u6cn/A/HtZV+KVjhRYTYUEblHg 8Hd7HFCViK1THBnW3WWXdzLQteSC1J6FVlyD81xKq4X5SHFUI7ZzXMfeST6q20J2WXMlpY511/C fYnfZzLZ5z2pwDpymj1QovvoMBwaAf+9dY6s+HEasgiR+1OFPJvFQAOYWAyUNqikKtna0sSomE2 Sp0tTIlZ9JspXcBWIGlGowFyYTXaO6Oklr6Ak1a0tw9M+8yIpd8dBtS/Uvdnn1v/9eZLbkORa0b VAACdHK8mwTr0IrhbGMJEq1H9JfWwKt6SH3cQ5oieu/yabXif+b0OMzd2URT2gWOeVX3BZfaUFx craGHISih89KopAVShHhS5clz6VmHa5xWOfo6elNiCNq4kZqbtIt8VAM3H58pV7m5dZWBZpmdHC 4fo84ODnvGLiDTWB1XmSl7iPLHJrwbYyiuq6otVReFzD6G+Rx2KXWloc8A+1RQLjU4dlvrZ3ifs 08UI58TIRtWOw== X-Received: by 2002:a05:600c:3b1a:b0:495:4d5c:903e with SMTP id 5b1f17b1804b1-49b91c2d8f3mr136960095e9.7.1787972490411; Fri, 28 Aug 2026 20:01:30 -0700 (PDT) Received: from kali ([169.224.126.247]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49b945816f2sm116637235e9.8.2026.08.28.20.01.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 28 Aug 2026 20:01:30 -0700 (PDT) From: Ali Firas To: netdev@vger.kernel.org Cc: kuba@kernel.org, pabeni@redhat.com, davem@davemloft.net, edumazet@google.com, andrew+netdev@lunn.ch, idosch@nvidia.com, razor@blackwall.org, stable@vger.kernel.org, linux-kernel@vger.kernel.org, Ali Firas Subject: [PATCH net] vxlan: vnifilter: validate the VNI range in vni_filter_entry_policy Date: Sat, 29 Aug 2026 06:00:41 +0300 Message-ID: <20260829030041.940594-1-alishmery18@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" VXLAN_VNIFILTER_ENTRY_START and VXLAN_VNIFILTER_ENTRY_END are declared as bare NLA_U32, so neither is range-checked before vxlan_process_vni_filter() passes them to vxlan_vni_add_del(): int v, err =3D 0; for (v =3D start_vni; v <=3D end_vni; v++) { v is int and end_vni is __u32, so the comparison is unsigned. With end_vni =3D=3D U32_MAX the loop cannot terminate through its own condition: v reaches U32_MAX, wraps to 0, and 0 <=3D U32_MAX is true again. Every iteration allocates a vxlan_vni_node plus a per-CPU vxlan_vni_stats_pcpu block until the machine is out of memory. Neither allocation carries __GFP_ACCOUNT, so the memory is not charged to the caller's memory cgroup, and the per-CPU block multiplies the cost by the number of CPUs. The rtnl_msg_handler entry for RTM_NEWTUNNEL carries no RTNL_FLAG_DOIT_UNLOCKED, so the loop runs holding rtnl_lock. rtnl_lock is global rather than per-netns, so for as long as the loop runs every network configuration operation on the host blocks, in every namespace. There is no cond_resched() in the loop either. The interface is reachable without privilege: creating the device and adding VNIs only requires CAP_NET_ADMIN in the network namespace's user namespace, so an unprivileged user inside unshare(CLONE_NEWUSER | CLONE_NEWNET) can trigger this with a single netlink message. A VNI at or above VXLAN_N_VID is also accepted and stored, although the VXLAN header carries only 24 bits. The MDB interface in the same driver already range-validates its VNI attributes with an identical constraint (vxlan_mdb.c, vni_range with .max =3D VXLAN_N_VID - 1). Apply the same validation here. Tested under KASAN in a 2G guest: before the change, adding the range 0-U32_MAX from an unprivileged user namespace drives a global OOM with the allocating task in vxlan_vnifilter_process(); after it, out-of-range values are rejected and the in-range case is unaffected. Reproducer available on request. Fixes: f9c4bb0b245c ("vxlan: vni filtering support on collect metadata devi= ce") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-6 [claude-code] Signed-off-by: Ali Firas --- drivers/net/vxlan/vxlan_vnifilter.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/drivers/net/vxlan/vxlan_vnifilter.c b/drivers/net/vxlan/vxlan_= vnifilter.c index dd94085e0886..9e86ac39cf9d 100644 --- a/drivers/net/vxlan/vxlan_vnifilter.c +++ b/drivers/net/vxlan/vxlan_vnifilter.c @@ -459,9 +459,15 @@ static int vxlan_vnifilter_dump(struct sk_buff *skb, s= truct netlink_callback *cb return err; } =20 +static const struct netlink_range_validation vni_filter_vni_range =3D { + .max =3D VXLAN_N_VID - 1, +}; + static const struct nla_policy vni_filter_entry_policy[VXLAN_VNIFILTER_ENT= RY_MAX + 1] =3D { - [VXLAN_VNIFILTER_ENTRY_START] =3D { .type =3D NLA_U32 }, - [VXLAN_VNIFILTER_ENTRY_END] =3D { .type =3D NLA_U32 }, + [VXLAN_VNIFILTER_ENTRY_START] =3D NLA_POLICY_FULL_RANGE(NLA_U32, + &vni_filter_vni_range), + [VXLAN_VNIFILTER_ENTRY_END] =3D NLA_POLICY_FULL_RANGE(NLA_U32, + &vni_filter_vni_range), [VXLAN_VNIFILTER_ENTRY_GROUP] =3D NLA_POLICY_EXACT_LEN(sizeof_field(struc= t iphdr, daddr)), [VXLAN_VNIFILTER_ENTRY_GROUP6] =3D NLA_POLICY_EXACT_LEN(sizeof(struct in6= _addr)), }; --=20 2.53.0