From nobody Mon Sep 28 21:08:04 2026 Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 79A9542FCAA for ; Mon, 17 Aug 2026 13:13:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786972382; cv=none; b=UCkl7H0UTo/5NArW6fmHvxcaU4Vp8dF2IDLXJ97DB1fUUFXTh8bEXWfTZhwBhcuN7mxIEL0zXTLVkdpY+a/+E63/XwoA+Jtu7zNdJqoBD+jL90d9llZ00Ywtys/O2J8Ohy4CyMNUO1geoNg/hY87S/XMP7ieUdKn0WAsXin1ZOU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786972382; c=relaxed/simple; bh=4QruugZiDYbn9n5UGyi2+FT6/ZrMmd+8+jAf5GVJ40w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WBjvx+Xqoy90XmN207UjDClSfCdHmE+i7QiHxIfkDPhbUXlSJZ6KQgBr+zY0hevOI9GUKb48tLGJxndOBlB4gzkoi3vCNrTD0LaicU6vdRa66rxbow3OdTOSr9oDOkSbWLS/VPdQhwVI3B8SDrJn/6mAGw0bF0/1NpJrUsm9OEc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=d5HhxuZM; arc=none smtp.client-ip=209.85.210.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="d5HhxuZM" Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-848643382fcso3456078b3a.1 for ; Mon, 17 Aug 2026 06:13:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1786972381; x=1787577181; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ata04BjbhgcCIeKGSAUINAv3LxYkBqq+xOXTmgSke4U=; b=d5HhxuZMGGzl2Qsg+ObR+FLw56RVRMVzUCa8Mhq+uEASyXueNbWy66l1zOoElAhRR+ 4GoOC0GlQ+YtyeQnsAn8FwebBgK8fZt/57csFZpt36I0rpPHJ3auMOclG3gQlpcMij2A 2DWOXCb1o3xagWro3iyI0VDSQrqQd5lcAfEuU/7xBVs9ZpNWoL6Np1L/LZPKtsnqlKZE yXRKKDmiAWIUHLTkXdT9Mq7sj3u2CHYdDHs8DNN/VRUQnMeAD7Lz02RHX0iDOTOqNRz0 gsp6SVQLV/rWVaeiQwe0qcD6+GAWIwMaUgxPNNmET0FzMH6WJPy0+VgQ8EFiiLDdX/sQ rc+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786972381; x=1787577181; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Ata04BjbhgcCIeKGSAUINAv3LxYkBqq+xOXTmgSke4U=; b=aEFv+bNk8fS4UTfrQZLM33NOZ1gBmBj9oq6/0bfyX89osBD54JWpqt9pR5oUFpLzve vyjw3q+mJekdImUMRzF2VOyLfJqIU5y+ISFp/F0uYwO5UecjcCbJ0LB6GaoP74JDN/De 1g+WkUGDg8uF60DZ9//8dm1xWgzu4VqUuw1Kl+NKGXngqL0fzNiUWvMF6vboixZCjUBO XsX1reuryLvuKZy7VeE6kER426nvDO8aYX3kDjVqmAGZ7Pl3wAmNRfLmmxayhoFhFuTn sZEHlBVnYu06BM9RRk5evzDt2B+JihuaD5uXeRUS6nZIGx4wbqt9HTR2fILoTQeu7k25 0M7w== X-Forwarded-Encrypted: i=1; AHgh+Rq6sM/gKjFISsS9oqxsTekaMUtC2pkmrwoGJ8MOPDBx7ncIOt2OCP+0jldgfiZCbsWE2b2g8XPMcLxAJD8=@vger.kernel.org X-Gm-Message-State: AOJu0YwAKzbjtme7xbJjgll81iXti4KETnKOAzfn80O5JzerqSS6fdIX urNvyp2i8RL0EIKN6uyZbusSkkE4g7Ix6i4tND6iBhxfghFCqZAOzs4O2LG8sRDAIN3C X-Gm-Gg: AR+sD103yHMPeTd6uy0Jfl5ZtEewjcjujtkt9FWZB0MNWsAshD+Gx1FyALUQHTkAjZs Tncuk6K6xFiGEDQDNeWvDiUyddRv02mITu69eq6ifsMi5Z0T5oHEhC2B0e2fxc1cOcxRf0jjUOX pKbiDnVn6AVH5B5VekZ+8hcKYedYuVzzQay5rs8C/kvzo/A9/P3CuX8u366o8HXjxAgHz4uV9ay HhsXmaEeTssSXSM0PQbCbkxTQ87pyfgYwYGsJ4ZTaxTHZwfY6an+VrlsnUvlzk7wJjc6AjeNzW7 PUwqaXYkYzAbIXpc0xSx/VzSJdMfxSapUxuNOWRJvz6ESIY3UoqnAONYHkS7/B+Ls3r9hpB5bQN QO4cLJnfDy/NfGYmTPBEMfQ5/bOX5DaSlDVSdAYTRGaVHrv7ChQc2bmc9UDb6A0D56S/m9UGlUu xDM8vr1JUFF+fHCgPcHia9Rkj/SW3zaSshfiGQgnvp7sb7yCCYyKEm3Q== X-Received: by 2002:a05:6a00:44cd:b0:847:8f8a:a05d with SMTP id d2e1a72fcca58-851b8906afcmr584528b3a.29.1786972380530; Mon, 17 Aug 2026 06:13:00 -0700 (PDT) Received: from gmail.com ([115.196.71.116]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-851b6fefb3asm261312b3a.53.2026.08.17.06.12.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 06:13:00 -0700 (PDT) From: Zihan Xi To: netdev@vger.kernel.org Cc: horms@kernel.org, davem@davemloft.net, pch@ordbogen.com, linux-kernel@vger.kernel.org, Zihan Xi , stable@vger.kernel.org, Vega Subject: [PATCH net 1/1] ipv4: Fix fib_rebalance() divide-by-zero race Date: Mon, 17 Aug 2026 13:12:10 +0000 Message-ID: <2080e22819c552b0d186563eda255a44c68404f7.1786812660.git.zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" fib_rebalance() reads ignore_routes_with_linkdown while summing active nexthop weights and then reads it again while calculating each upper bound. Sysctl writes are not serialized by RTNL. If all nexthops are link-down, a concurrent 1-to-0 change can leave total at zero and make the second pass divide by zero. Route insertion and link-state updates call fib_rebalance() under RTNL, and netlink devconf changes are already protected by RTNL. Make the sysctl handler take the per-net RTNL lock before changing ignore_routes_with_linkdown. This gives both passes a stable policy view without adding work to route lookup or rebalance paths. Fixes: 0e884c78ee19 ("ipv4: L3 hash-based multipath") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: Codex:gpt-5.4 Signed-off-by: Zihan Xi --- net/ipv4/devinet.c | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/net/ipv4/devinet.c b/net/ipv4/devinet.c index a35b72662..71d961013 100644 --- a/net/ipv4/devinet.c +++ b/net/ipv4/devinet.c @@ -2604,6 +2604,23 @@ static int devinet_conf_proc(const struct ctl_table = *ctl, int write, return ret; } =20 +static int devinet_conf_proc_rtnl(const struct ctl_table *ctl, int write, + void *buffer, size_t *lenp, loff_t *ppos) +{ + struct net *net =3D ctl->extra2; + int ret; + + if (write && !rtnl_net_trylock(net)) + return restart_syscall(); + + ret =3D devinet_conf_proc(ctl, write, buffer, lenp, ppos); + + if (write) + rtnl_net_unlock(net); + + return ret; +} + static int devinet_sysctl_forward(const struct ctl_table *ctl, int write, void *buffer, size_t *lenp, loff_t *ppos) { @@ -2709,8 +2726,9 @@ static struct devinet_sysctl_table { "igmpv2_unsolicited_report_interval"), DEVINET_SYSCTL_RW_ENTRY(IGMPV3_UNSOLICITED_REPORT_INTERVAL, "igmpv3_unsolicited_report_interval"), - DEVINET_SYSCTL_RW_ENTRY(IGNORE_ROUTES_WITH_LINKDOWN, - "ignore_routes_with_linkdown"), + DEVINET_SYSCTL_COMPLEX_ENTRY(IGNORE_ROUTES_WITH_LINKDOWN, + "ignore_routes_with_linkdown", + devinet_conf_proc_rtnl), DEVINET_SYSCTL_RW_ENTRY(DROP_GRATUITOUS_ARP, "drop_gratuitous_arp"), DEVINET_SYSCTL_RW_ENTRY(NOXFRM, "disable_xfrm"), --=20 2.43.0