|
|
dbdd24 |
From bdeb7f1c4651240043b0b8a2a5432fc9760cfadf Mon Sep 17 00:00:00 2001
|
|
|
dbdd24 |
From: Joe Lawrence <joe.lawrence@redhat.com>
|
|
|
dbdd24 |
Date: Wed, 15 Jun 2022 16:10:31 -0400
|
|
|
dbdd24 |
Subject: [KPATCH CVE-2022-1966] kpatch fixes for CVE-2022-1966
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Kernels:
|
|
|
dbdd24 |
3.10.0-1160.36.2.el7
|
|
|
dbdd24 |
3.10.0-1160.41.1.el7
|
|
|
dbdd24 |
3.10.0-1160.42.2.el7
|
|
|
dbdd24 |
3.10.0-1160.45.1.el7
|
|
|
dbdd24 |
3.10.0-1160.49.1.el7
|
|
|
dbdd24 |
3.10.0-1160.53.1.el7
|
|
|
dbdd24 |
3.10.0-1160.59.1.el7
|
|
|
dbdd24 |
3.10.0-1160.62.1.el7
|
|
|
dbdd24 |
3.10.0-1160.66.1.el7
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Changes since last build:
|
|
|
dbdd24 |
arches: x86_64 ppc64le
|
|
|
dbdd24 |
nf_tables_api.o: changed function: nft_expr_init
|
|
|
dbdd24 |
nft_dynset.o: changed function: nft_dynset_init
|
|
|
dbdd24 |
---------------------------
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Kpatch-MR: https://gitlab.com/redhat/prdsc/rhel/src/kpatch/rhel-7/-/merge_requests/42
|
|
|
dbdd24 |
Approved-by: Yannick Cote (@ycote1)
|
|
|
dbdd24 |
Modifications: none
|
|
|
dbdd24 |
|
|
|
dbdd24 |
commit c511e60bebd0546f8ec47a3c1691ab01d262b8e4
|
|
|
dbdd24 |
Author: Phil Sutter <psutter@redhat.com>
|
|
|
dbdd24 |
Date: Fri Jun 3 16:54:42 2022 +0200
|
|
|
dbdd24 |
|
|
|
dbdd24 |
netfilter: nf_tables: fix memory leak if expr init fails
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2093000
|
|
|
dbdd24 |
Upstream Status: commit 6cafaf4764a32
|
|
|
dbdd24 |
|
|
|
dbdd24 |
commit 6cafaf4764a32597c2195aa5411b87728e1fde8a
|
|
|
dbdd24 |
Author: Liping Zhang <liping.zhang@spreadtrum.com>
|
|
|
dbdd24 |
Date: Mon Jun 20 21:11:45 2016 +0800
|
|
|
dbdd24 |
|
|
|
dbdd24 |
netfilter: nf_tables: fix memory leak if expr init fails
|
|
|
dbdd24 |
|
|
|
dbdd24 |
If expr init fails then we need to free it.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
So when the user add a nft rule as follows:
|
|
|
dbdd24 |
|
|
|
dbdd24 |
# nft add rule filter input tcp dport 22 flow table ssh \
|
|
|
dbdd24 |
{ ip saddr limit rate 0/second }
|
|
|
dbdd24 |
|
|
|
dbdd24 |
memory leak will happen.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Signed-off-by: Liping Zhang <liping.zhang@spreadtrum.com>
|
|
|
dbdd24 |
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Signed-off-by: Phil Sutter <psutter@redhat.com>
|
|
|
dbdd24 |
|
|
|
dbdd24 |
commit 4a4cc18bcf8f43c93dbf39cb52308dfaea4ec346
|
|
|
dbdd24 |
Author: Phil Sutter <psutter@redhat.com>
|
|
|
dbdd24 |
Date: Fri Jun 3 16:54:43 2022 +0200
|
|
|
dbdd24 |
|
|
|
dbdd24 |
netfilter: nf_tables: disallow non-stateful expression in sets earlier
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2093000
|
|
|
dbdd24 |
Upstream Status: net.git commit 520778042ccca
|
|
|
dbdd24 |
CVE: CVE-2022-1966
|
|
|
dbdd24 |
Conflicts:
|
|
|
dbdd24 |
* RHEL7 does not have nft_set_elem_expr_alloc(), remove
|
|
|
dbdd24 |
NFT_EXPR_STATEFUL check from nft_dynset_init() instead
|
|
|
dbdd24 |
* Context change in nft_expr_init() as RHEL7 does not have .release_ops
|
|
|
dbdd24 |
* Adjusted new NFT_EXPR_STATEFUL check as upstream renamed 'info' into
|
|
|
dbdd24 |
'expr_info'
|
|
|
dbdd24 |
|
|
|
dbdd24 |
commit 520778042ccca019f3ffa136dd0ca565c486cedd
|
|
|
dbdd24 |
Author: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
|
dbdd24 |
Date: Wed May 25 10:36:38 2022 +0200
|
|
|
dbdd24 |
|
|
|
dbdd24 |
netfilter: nf_tables: disallow non-stateful expression in sets earlier
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Since 3e135cd499bf ("netfilter: nft_dynset: dynamic stateful expression
|
|
|
dbdd24 |
instantiation"), it is possible to attach stateful expressions to set
|
|
|
dbdd24 |
elements.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
cd5125d8f518 ("netfilter: nf_tables: split set destruction in deactivate
|
|
|
dbdd24 |
and destroy phase") introduces conditional destruction on the object to
|
|
|
dbdd24 |
accomodate transaction semantics.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
nft_expr_init() calls expr->ops->init() first, then check for
|
|
|
dbdd24 |
NFT_STATEFUL_EXPR, this stills allows to initialize a non-stateful
|
|
|
dbdd24 |
lookup expressions which points to a set, which might lead to UAF since
|
|
|
dbdd24 |
the set is not properly detached from the set->binding for this case.
|
|
|
dbdd24 |
Anyway, this combination is non-sense from nf_tables perspective.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
This patch fixes this problem by checking for NFT_STATEFUL_EXPR before
|
|
|
dbdd24 |
expr->ops->init() is called.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
The reporter provides a KASAN splat and a poc reproducer (similar to
|
|
|
dbdd24 |
those autogenerated by syzbot to report use-after-free errors). It is
|
|
|
dbdd24 |
unknown to me if they are using syzbot or if they use similar automated
|
|
|
dbdd24 |
tool to locate the bug that they are reporting.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
For the record, this is the KASAN splat.
|
|
|
dbdd24 |
|
|
|
dbdd24 |
[ 85.431824] ==================================================================
|
|
|
dbdd24 |
[ 85.432901] BUG: KASAN: use-after-free in nf_tables_bind_set+0x81b/0xa20
|
|
|
dbdd24 |
[ 85.433825] Write of size 8 at addr ffff8880286f0e98 by task poc/776
|
|
|
dbdd24 |
[ 85.434756]
|
|
|
dbdd24 |
[ 85.434999] CPU: 1 PID: 776 Comm: poc Tainted: G W 5.18.0+ #2
|
|
|
dbdd24 |
[ 85.436023] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Fixes: 0b2d8a7b638b ("netfilter: nf_tables: add helper functions for expression handling")
|
|
|
dbdd24 |
Reported-and-tested-by: Aaron Adams <edg-e@nccgroup.com>
|
|
|
dbdd24 |
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Signed-off-by: Phil Sutter <psutter@redhat.com>
|
|
|
dbdd24 |
|
|
|
dbdd24 |
Signed-off-by: Joe Lawrence <joe.lawrence@redhat.com>
|
|
|
dbdd24 |
---
|
|
|
dbdd24 |
net/netfilter/nf_tables_api.c | 16 +++++++++++-----
|
|
|
dbdd24 |
net/netfilter/nft_dynset.c | 4 ----
|
|
|
dbdd24 |
2 files changed, 11 insertions(+), 9 deletions(-)
|
|
|
dbdd24 |
|
|
|
dbdd24 |
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
|
|
|
dbdd24 |
index 0f46d90715a3..44738b987690 100644
|
|
|
dbdd24 |
--- a/net/netfilter/nf_tables_api.c
|
|
|
dbdd24 |
+++ b/net/netfilter/nf_tables_api.c
|
|
|
dbdd24 |
@@ -1739,21 +1739,27 @@ struct nft_expr *nft_expr_init(const struct nft_ctx *ctx,
|
|
|
dbdd24 |
|
|
|
dbdd24 |
err = nf_tables_expr_parse(ctx, nla, &info;;
|
|
|
dbdd24 |
if (err < 0)
|
|
|
dbdd24 |
- goto err1;
|
|
|
dbdd24 |
+ goto err_expr_parse;
|
|
|
dbdd24 |
+
|
|
|
dbdd24 |
+ err = -EOPNOTSUPP;
|
|
|
dbdd24 |
+ if (!(info.ops->type->flags & NFT_EXPR_STATEFUL))
|
|
|
dbdd24 |
+ goto err_expr_stateful;
|
|
|
dbdd24 |
|
|
|
dbdd24 |
err = -ENOMEM;
|
|
|
dbdd24 |
expr = kzalloc(info.ops->size, GFP_KERNEL);
|
|
|
dbdd24 |
if (expr == NULL)
|
|
|
dbdd24 |
- goto err2;
|
|
|
dbdd24 |
+ goto err_expr_stateful;
|
|
|
dbdd24 |
|
|
|
dbdd24 |
err = nf_tables_newexpr(ctx, &info, expr);
|
|
|
dbdd24 |
if (err < 0)
|
|
|
dbdd24 |
- goto err2;
|
|
|
dbdd24 |
+ goto err_expr_new;
|
|
|
dbdd24 |
|
|
|
dbdd24 |
return expr;
|
|
|
dbdd24 |
-err2:
|
|
|
dbdd24 |
+err_expr_new:
|
|
|
dbdd24 |
+ kfree(expr);
|
|
|
dbdd24 |
+err_expr_stateful:
|
|
|
dbdd24 |
module_put(info.ops->type->owner);
|
|
|
dbdd24 |
-err1:
|
|
|
dbdd24 |
+err_expr_parse:
|
|
|
dbdd24 |
return ERR_PTR(err);
|
|
|
dbdd24 |
}
|
|
|
dbdd24 |
|
|
|
dbdd24 |
diff --git a/net/netfilter/nft_dynset.c b/net/netfilter/nft_dynset.c
|
|
|
dbdd24 |
index 3f9f8e82716e..0cf187230050 100644
|
|
|
dbdd24 |
--- a/net/netfilter/nft_dynset.c
|
|
|
dbdd24 |
+++ b/net/netfilter/nft_dynset.c
|
|
|
dbdd24 |
@@ -174,10 +174,6 @@ static int nft_dynset_init(const struct nft_ctx *ctx,
|
|
|
dbdd24 |
priv->expr = nft_expr_init(ctx, tb[NFTA_DYNSET_EXPR]);
|
|
|
dbdd24 |
if (IS_ERR(priv->expr))
|
|
|
dbdd24 |
return PTR_ERR(priv->expr);
|
|
|
dbdd24 |
-
|
|
|
dbdd24 |
- err = -EOPNOTSUPP;
|
|
|
dbdd24 |
- if (!(priv->expr->ops->type->flags & NFT_EXPR_STATEFUL))
|
|
|
dbdd24 |
- goto err1;
|
|
|
dbdd24 |
} else if (set->flags & NFT_SET_EVAL)
|
|
|
dbdd24 |
return -EINVAL;
|
|
|
dbdd24 |
|
|
|
dbdd24 |
--
|
|
|
dbdd24 |
2.34.3
|
|
|
dbdd24 |
|
|
|
dbdd24 |
|