The relay queues its General Query on the amt device with a raw tunnel pointer in skb->cb, and a query that waits in a qdisc can outlive its tunnel: a use-after-free in amt_dev_xmit(), reported by Microsoft with a KASAN reproducer. Patch 1 sends the query directly from amt_request_handler(), inside the RCU section that found or created the tunnel, so it never waits in a qdisc and nothing is stored in skb->cb.
Patch 2 adds the selftest Taehee asked for. It counts the queries that leave the relay through its amt device and expects none. It fails without patch 1 and passes with it. v4: patch 1 is unchanged from v3; patch 2 is new. v3: https://lore.kernel.org/netdev/[email protected]/ v2: https://lore.kernel.org/netdev/[email protected]/ Omar Ramadan (2): amt: send the relay's General Query directly from the receive path selftests: net: amt: check that the relay's queries bypass the amt device drivers/net/amt.c | 48 ++++++++++-------------------- include/net/amt.h | 4 --- tools/testing/selftests/net/amt.sh | 29 ++++++++++++++++++ 3 files changed, 44 insertions(+), 37 deletions(-) base-commit: a7bfaba4823e3c165bb2004c74eff7c096672bc7 -- 2.47.3

