From patchwork Tue Jul 28 11:48:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 5148 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp485564mac; Tue, 28 Jul 2026 04:49:20 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rq/1MgU9l5zXaau+b7ihIwOUVfG3LtwZmI0dCvDi+kCIkQS0Iq6Z0gP8W/Eu+h2IVIktt9U4tHIbFE=@openvpn.net X-Received: by 2002:a05:6870:a1a5:b0:451:cba2:10ad with SMTP id 586e51a60fabf-4586cacca31mr1001245fac.20.1785239360685; Tue, 28 Jul 2026 04:49:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785239360; cv=none; d=google.com; s=arc-20260327; b=HE7tszRHp4ybTj16ni3w2bmLDu6+YAjqm8vBjewkIJmctU8qimDcBNm8IZ90Ltkyt1 SpgBYlGAIEC6OVTtfvIBWszbj/AsjFN4iLRCGWcSpYy4PrgE/TSC6n1eNDEgP2iHNOdt Zg5b+k7EJtV2H4Eil1B9uTNnuqIvggB66ZT5JLUxfmrE5evNSoceXWxtkhY5o0ei4h5y 8QZRgEPhFYMqXwIsiX+fdS7+Ui8lfCQuGFtsNFYo9AKnrfzPYZp/io7Lpn1O0xCNwuK4 DgIVBHNup/P9EBmdJOhDTdZa8DMHGlTIVIzvwqL5F4rUxx0EYzfW2h1ADd1Tvvp4lNH+ 6CTg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=Oj8Z5EuLMRxrE2iZMLlUC+4BrcJM5h7LPIlkZgChsak=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=qGlvYi5Tua0EU90SKWckBpoebVg7fUWGiHrJBt3BufvarznPnR0giAmmTPC71/20Pi 4zQHi5TOqh1ofd1CYuwYUCeJadsxCaKQWLKE6qTsDY2AJxyYcrD8A0Z+5ZEJ+V1B1zsn GNwS6y9IBKRHgrG8jYv6DzRQWn6lq4mK2HQcuoYgW9/n7/TsN8QgSdaRXqDPp3XBUpTP emcPQoWEMw7+F5FN6HbRVOBb4ZaKgEWKo658erNf8w9QfwfAZ49IkcYl8tX1ZiPLDYlW 8+PjrEqEjKl4Wa+OJmDc8KhWr//54rn2TwXZEPfgHgxFLKzMPAzRmMHCUQse8dBR1LOe TLFw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Z9ASxpMo; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="RfR/lFoE"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="c/nMSEP1"; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=innx1MXg; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-457aa1916c0si14722864fac.23.2026.07.28.04.49.20 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 28 Jul 2026 04:49:20 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Z9ASxpMo; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="RfR/lFoE"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="c/nMSEP1"; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=innx1MXg; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Oj8Z5EuLMRxrE2iZMLlUC+4BrcJM5h7LPIlkZgChsak=; b=Z9ASxpMo+VhFi/W9NAu9+ZBP6V 0fMwymfJVM0RXBKKWxhZX8CCTMjUt71uM/IdEyMqA5AiRoJSDgdDTPLyUELuP2ZrbSURbmDmY+phB KY3LZdjVQfun6S3WaZ9azKGGpXqri79V2cmAbOiENQPi1GaeqWM+m/CUh1TcJ+EDNpPY=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wogJE-0005u1-MR; Tue, 28 Jul 2026 11:49:18 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wogJC-0005tm-Kz for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:16 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=RfR/lFoExguXPt5pDF1Q2td/Qi KXwTsYRt0Jd0eV8G3fUiSI4hQsJS7KoXEFkpISs9YoMJP3Kun0udLtk6rvcqEOnG6JmgtTd1ROLDL o0yI9KkcRgkXBVNbbWGgARSgO+AY6MRR9zICObKyscZQffIwKVbjgEW4CatofjuqYIwA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=c/nMSEP1+ykwDqu/hqhwdbj4dv FlwYidV1RDpkGlynJnbwLZbbWdCQtA3vjQ1FpnwqyVCKBPMO4QXrtgNUT6APwEANK1I6HWMyGO3Vo /4Kt/S7hn3DlXActe+aCWtq96CAKSSGFS8IgLEVeivLzA44WiT7xGIppWboVp+gfBhsE=; Received: from mout-p-103.mailbox.org ([80.241.56.161]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wogJ8-0003Bm-OM for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:16 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-103.mailbox.org (Postfix) with ESMTPS id 4h8Ydq5DD0zKnVJ; Tue, 28 Jul 2026 13:49:03 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785239343; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ixElgIOpjex/L7zdwx7lUWOiWK5w4EbBc2Uvh57Z4fI=; b=innx1MXgJawRmiOXavFrlkBE5FebLjSyZKJY4RAsQkqB98DHfAecbvYD+M6xw2ingIfiDr yuV34c/XEj2xPeEXMLjqi5xcqDpQ0+KaDnjicLkLdvUq8nY4Fe5m/HHvoLD9BHmPv4klHV cooyMUrhbQdsqyaf0y2LvaHkN1PO4RiW10Vy470VDGTkms8ZtWJewHt47n+a4HD9wEUAmB dhi4kZ8HVBvBFqZDx9jbQrGK/othnHKJUxPTxO3grByEpH3E41Ou+IHc4SnWhqZeqbkRmR nhsU3G2vHa15NB/3dpctLWNxBdGGIQyRbJMKwKDiatae6B9rJK6qm+g5kAlGsA== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of a@unstable.cc designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=a@unstable.cc From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Tue, 28 Jul 2026 13:48:50 +0200 Message-ID: <20260728114855.1323861-5-a@unstable.cc> In-Reply-To: <20260728114855.1323861-1-a@unstable.cc> References: <20260728114855.1323861-1-a@unstable.cc> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h8Ydq5DD0zKnVJ X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.161 listed in wl.mailspike.net] 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1wogJ8-0003Bm-OM Subject: [Openvpn-devel] [PATCH ovpn net v4 4/9] ovpn: ensure socket is owned by ovpn before deref sk_user_data X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871959147759548193 X-GMAIL-MSGID: 1871959147759548193 From: Antonio Quartulli Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Failing to do so may lead to out-of-bounds reads. Fixes: f6226ae7a0cd ("ovpn: introduce the ovpn_socket object") Signed-off-by: Antonio Quartulli --- drivers/net/ovpn/socket.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/net/ovpn/socket.c b/drivers/net/ovpn/socket.c index 517caa64a4fe..6cbeb2caaeec 100644 --- a/drivers/net/ovpn/socket.c +++ b/drivers/net/ovpn/socket.c @@ -162,6 +162,15 @@ struct ovpn_socket *ovpn_socket_new(struct socket *sock, struct ovpn_peer *peer) rcu_read_lock(); ovpn_sock = rcu_dereference_sk_user_data(sk); if (ovpn_sock) { + /* something else filled the sk_user_data without + * setting the encap_type. Reject the socket. + */ + if (!type) { + ovpn_sock = ERR_PTR(-EBUSY); + rcu_read_unlock(); + goto sock_release; + } + /* socket owned by another ovpn instance, we can't use it */ if (ovpn_sock->ovpn != peer->ovpn) { ovpn_sock = ERR_PTR(-EBUSY);