From patchwork Mon Jul 27 20:07:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 5130 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:190f:b0:87d:a69c:34be with SMTP id g15csp1598655maz; Mon, 27 Jul 2026 13:07:29 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RozkHdF5HZIfpJYS0VJreYsL+Vv17ppISSdQaSw43KguIf4MXfVoRRcPpqvX252hQ3IG/jIXFgtmnE=@openvpn.net X-Received: by 2002:a9d:4c86:0:b0:7eb:c618:434f with SMTP id 46e09a7af769-7effa7e13b9mr149589a34.0.1785182849735; Mon, 27 Jul 2026 13:07:29 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785182849; cv=none; d=google.com; s=arc-20260327; b=KZdHdmJIi9wn5cvDJqvDV7b8BXKTRAupF/uqOWRWVeu+y9X/ojS+gfsuyR+/pmZHjr S7lazClkOso3GdtmN7KZfatxD8ci/daAImWF+4ehQkvlWHuoVwaHP4JSZEUywCLmnxIw FG/JnrbjO0zlDvcXaTAg0zIka103ODab5eheKZoV9NPGygniz+OF2gk3lvi5Bry1ZGn4 j+FaZnEjoBpopfmeRHPezbliMrWQAx+yh1nXZaQupZvxKOQkQZQFLiSRl4K8vfWBwRSU Ph9W2kDLpvLzbmz9YawAUywOMlkCUTC+2jCa++MQDncEmBaHmT7rAkcV8nfsc8shqt4o aUJw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=Oj8Z5EuLMRxrE2iZMLlUC+4BrcJM5h7LPIlkZgChsak=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=Zh6Z+G23R4gM39AA8W3s8W49k2EYqaOf+780lspNniGL61NWUoDbQ/XOrtOEjJ9okC R7J2E6NA7+/TFfnpGY4470oP6LuyecpvkeXCfcrG8WATiYw7XbXW0blOyAPEnYWFh6vV eYbmMzXXDm/fhzFMx448eMbdldVfIQsM6wkTOh/Wr6olwfxaFaZ4tjtE80/NpsqhisCz TSx1sHKBgr8oMHozG4v5+vwm4/Z0qpQPM61+ZjFZSCq0+XBSOdJ9qzhg2DRKxUljb6Nu 5QMZhd/sxXWEEEQHDhXY/7ZCoZmsefhbX6i6kxXShjYCDnKuaKDMlGhMtsRxOYoyCFwb yYgA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="cEGA4/KN"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Jl5Ek1zt; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=X3xT1Izo; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=LLfawQVS; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7ee49e15ebbsi11073987a34.69.2026.07.27.13.07.29 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 27 Jul 2026 13:07:29 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="cEGA4/KN"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Jl5Ek1zt; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=X3xT1Izo; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=LLfawQVS; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Oj8Z5EuLMRxrE2iZMLlUC+4BrcJM5h7LPIlkZgChsak=; b=cEGA4/KN2QM+drzV8fmc6reilm J49x/FyO9mCsXmvKzCY1jICG9Xks4uHnLGLekUErdy+jlxGDG9AcP8leuSeVkCWLGnE6yBIwkGRZM Ad5lKzb+j/DmmRbvwP/F/aCy/41XV2HwkUuLGmf/caPbm1iYyGulaICP+Ii5VCkWcxhM=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1woRbh-00063U-O3; Mon, 27 Jul 2026 20:07:26 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1woRbg-000638-6N for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:24 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=Jl5Ek1ztTDc7FaZvJLO+L8nbS6 cu8W3c/9a7W61y5dreEuY+Mh9LUkk7DIlL5gH1P2Y/25KNW4uyw6thdCL5nPShZNGmW2buAUZRZ50 frm+jWI3Alno0CLvTO3Ra/HPGuobrR5ptgFFrfoxoSLWA5v5kj74wNcppdaGfSxTwPSQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=X3xT1IzoUZKZKgxVuMq6dvt6Ri HPFhYbJhUydiUDb7lFyu0kzwy0PaSo+XJX89MYaW+b/DCIrvUex+yjSB4TkGTb2y9+tLiLhYGcmEE OXnNH/Eqa3HkPUhygQ6XuGJBxlkWOkT5t8qhXgqr20NX8sNrIAToAIET2gLXDVESfotk=; Received: from mout-p-102.mailbox.org ([80.241.56.152]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1woRbi-0002cp-Nt for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:24 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-102.mailbox.org (Postfix) with ESMTPS id 4h88l74C05zKw2N; Mon, 27 Jul 2026 22:07:15 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785182835; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=LLfawQVSg+Y4jKWZP/gc/QI0SHIcuFoAZcvH5Uv/wMZw3M9GF1zqqZDPEkCSrvEkdDkAXH susfja5Q1P6qia15s8qy+qMe9u59ByYvi4ZXcgVY3bMTqULknsX/jV3c9wA8hrkz7CiT9x 8T4dHmYV9y8GajFahxZ2XUdnf99FwM1Viy5CybQaHrRv5K8bunvR6Qn+gG6wsZ0jEUwIcO 7/58gmmuucu6H24dxk0qRPHrbKxzrjLenA2LuqU4xx66vw0hOCa/hi51e2MqqBHXmxa25F KBp6yWMC83ibFUn0HwhrSIIoeP+QLHq+HCH0VfEFGU6paafbPPAFFDZnWlrKcg== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of a@unstable.cc designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=a@unstable.cc From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Mon, 27 Jul 2026 22:07:00 +0200 Message-ID: <20260727200705.869169-5-a@unstable.cc> In-Reply-To: <20260727200705.869169-1-a@unstable.cc> References: <20260727200705.869169-1-a@unstable.cc> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h88l74C05zKw2N X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.152 listed in wl.mailspike.net] -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1woRbi-0002cp-Nt Subject: [Openvpn-devel] [PATCH ovpn net v3 4/9] ovpn: ensure socket is owned by ovpn before deref sk_user_data X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871899892164428237 X-GMAIL-MSGID: 1871899892164428237 From: Antonio Quartulli Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Failing to do so may lead to out-of-bounds reads. Fixes: f6226ae7a0cd ("ovpn: introduce the ovpn_socket object") Signed-off-by: Antonio Quartulli --- drivers/net/ovpn/socket.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/net/ovpn/socket.c b/drivers/net/ovpn/socket.c index 517caa64a4fe..6cbeb2caaeec 100644 --- a/drivers/net/ovpn/socket.c +++ b/drivers/net/ovpn/socket.c @@ -162,6 +162,15 @@ struct ovpn_socket *ovpn_socket_new(struct socket *sock, struct ovpn_peer *peer) rcu_read_lock(); ovpn_sock = rcu_dereference_sk_user_data(sk); if (ovpn_sock) { + /* something else filled the sk_user_data without + * setting the encap_type. Reject the socket. + */ + if (!type) { + ovpn_sock = ERR_PTR(-EBUSY); + rcu_read_unlock(); + goto sock_release; + } + /* socket owned by another ovpn instance, we can't use it */ if (ovpn_sock->ovpn != peer->ovpn) { ovpn_sock = ERR_PTR(-EBUSY);