tree e7502ee5ed132e7d1ff00bcd75120f7a6354114e
parent ab6fae2fe8466a54f59b075ba87ac9c699b0cd44
author M A Ramdhan <ramdhan@starlabs.sg> 1688573730 -0400
committer Anil Altinay <aaltinay@google.com> 1690987292 +0000

net/sched: cls_fw: Fix improper refcount update leads to use-after-free

[ Upstream commit 0323bce598eea038714f941ce2b22541c46d488f ]

In the event of a failure in tcf_change_indev(), fw_set_parms() will
immediately return an error after incrementing or decrementing
reference counter in tcf_bind_filter().  If attacker can control
reference counter to zero and make reference freed, leading to
use after free.

In order to prevent this, move the point of possible failure above the
point where the TC_FW_CLASSID is handled.

BUG=b/293910383
TEST=presubmit
RELEASE_NOTE=Fixed CVE-2023-3776 in the Linux kernel.

cos-patch: security-high
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: M A Ramdhan <ramdhan@starlabs.sg>
Signed-off-by: M A Ramdhan <ramdhan@starlabs.sg>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Pedro Tammela <pctammela@mojatatu.com>
Message-ID: <20230705161530.52003-1-ramdhan@starlabs.sg>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Change-Id: I445b399022828fed7d085d8e03915ec38a80a55c
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/53512
Reviewed-by: Oleksandr Tymoshenko <ovt@google.com>
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
