• Francesco Ruggeri's avatar
    net: race condition in ipv6 forwarding and disable_ipv6 parameters · 013d97e9
    Francesco Ruggeri authored
    There is a race condition in addrconf_sysctl_forward() and
    addrconf_sysctl_disable().
    These functions change idev->cnf.forwarding (resp. idev->cnf.disable_ipv6)
    and then try to grab the rtnl lock before performing any actions.
    If that fails they restore the original value and restart the syscall.
    This creates race conditions if ipv6 code tries to access
    these parameters, or if multiple instances try to do the same operation.
    As an example of the former, if __ipv6_ifa_notify() finds a 0 in
    idev->cnf.forwarding when invoked by addrconf_ifdown() it may not free
    anycast addresses, ultimately resulting in the net_device not being freed.
    This patch reads the user parameters into a temporary location and only
    writes the actual parameters when the rtnl lock is acquired.
    Tested in 2.6.38.8.
    Signed-off-by: default avatarFrancesco Ruggeri <fruggeri@aristanetworks.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    013d97e9
addrconf.c 115 KB