netfilter: fix use-after-free in NF_HOOK_LIST
authorEdward Cree <ecree@solarflare.com>
Mon, 9 Jul 2018 17:10:02 +0000 (18:10 +0100)
committerDavid S. Miller <davem@davemloft.net>
Mon, 9 Jul 2018 21:55:53 +0000 (14:55 -0700)
nf_hook() can free the skb, so we need to remove it from the list before
 calling, and add passed skbs to a sublist afterwards.

Fixes: 17266ee93984 ("net: ipv4: listified version of ip_rcv")
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Edward Cree <ecree@solarflare.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/linux/netfilter.h

index 5a5e0a2ab2a35be8b9060918f94bcb280fc4abb2..23b48de8c2e2a3ce667a3571cb59bdef3eb69801 100644 (file)
@@ -294,12 +294,16 @@ NF_HOOK_LIST(uint8_t pf, unsigned int hook, struct net *net, struct sock *sk,
             int (*okfn)(struct net *, struct sock *, struct sk_buff *))
 {
        struct sk_buff *skb, *next;
+       struct list_head sublist;
 
+       INIT_LIST_HEAD(&sublist);
        list_for_each_entry_safe(skb, next, head, list) {
-               int ret = nf_hook(pf, hook, net, sk, skb, in, out, okfn);
-               if (ret != 1)
-                       list_del(&skb->list);
+               list_del(&skb->list);
+               if (nf_hook(pf, hook, net, sk, skb, in, out, okfn) == 1)
+                       list_add_tail(&skb->list, &sublist);
        }
+       /* Put passed packets back on main list */
+       list_splice(&sublist, head);
 }
 
 /* Call setsockopt() */