On 31/08/2026 15:52, 赵世荣 wrote:
Agreed, Eric's patch fixes the root cause properly. Please disregard
my patch.
Apologies for the noise. I'll review the mailing list and verify the
root cause before sending next time.
Thanks,
Zhao ShiRong
Also don't top post on netdev@, reply below.
Thanks,
Nik
At 2026-08-31 20:31:19, "Nikolay Aleksandrov" <[email protected]> wrote:
On 31/08/2026 14:30, Zhao ShiRong wrote:
Packets locally delivered by the bridge are re-injected into the
receive path via br_pass_frame_up() -> br_netif_receive_skb() ->
netif_receive_skb() with skb->dev set to the bridge device. If the
bridge device has an XDP program attached, __netif_receive_skb_core()
runs do_xdp_generic() a second time on such packets.
A locally-delivered packet that was allocated on the TX path (e.g. an
MLD packet built by mld_newpack()) does not carry the
XDP_PACKET_HEADROOM that generic XDP requires, so
netif_skb_check_for_xdp() calls pskb_expand_head() and reallocates the
skb head buffer. This frees the head that the bridge rx path
(br_handle_frame() / br_handle_frame_finish()) is still using, leading
to a use-after-free read in br_handle_frame():
BUG: KASAN: slab-use-after-free in is_multicast_ether_addr [inline]
BUG: KASAN: slab-use-after-free in is_valid_ether_addr [inline]
BUG: KASAN: slab-use-after-free in br_handle_frame+0xcfb/0x1510
net/bridge/br_input.c:349
netif_receive_generic_xdp() already refuses to run generic XDP on
reinjected packets by checking skb_is_redirected(). Reuse that marker:
set it right before the bridge re-injects the packet, so generic XDP is
skipped and the head buffer is left intact.
Reported-by: [email protected]
Link:
https://lore.kernel.org/all/[email protected]/T/
Signed-off-by: Zhao ShiRong <[email protected]>
---
net/bridge/br_input.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/bridge/br_input.c b/net/bridge/br_input.c
--- a/net/bridge/br_input.c
+++ b/net/bridge/br_input.c
@@ -26,6 +26,12 @@ static int
br_netif_receive_skb(struct net *net, struct sock *sk, struct sk_buff *skb)
{
br_drop_fake_rtable(skb);
+
+ /* Re-injected for local delivery: do not let generic XDP run on the
+ * bridge device a second time, it could reallocate the head via
+ * pskb_expand_head() and free a buffer still in use.
+ */
+ skb_set_redirected_noclear(skb, false);
return netif_receive_skb(skb);
}
--
2.43.0
Nacked-by: Nikolay Aleksandrov <[email protected]>
This is wrong on multiple levels, use your head for 2 seconds before blindly
sending AI crap. This was sent ~2 hours after the report was sent, did you
even test your patch or just hit send? Very disturbing practice anyway.
Perhaps we should clone the skb for passing it up to the bridge when a fwding
helper is using it (i.e. when there are actually clones).