In the Linux kernel, the following vulnerability has been resolved: net: esp: fix bad handling of pages from pagepool When the skb is reorganized during espoutput (!esp->inline), the pages coming from the original skb fragments are supposed to be released back to the system through putpage. But if the skb fragment pages are originating from a pagepool, calling putpage on them will trigger a pagepool leak which will eventually result in a crash. This leak can be easily observed when using CONFIGDEBUGVM and doing ipsec + gre (non offloaded) forwarding: BUG: Bad page state in process ksoftirqd/16 pfn:1451b6 page:00000000de2b8d32 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1451b6000 pfn:0x1451b6 flags: 0x200000000000000(node=0|zone=2) pagetype: 0xffffffff() raw: 0200000000000000 dead000000000040 ffff88810d23c000 0000000000000000 raw: 00000001451b6000 0000000000000001 00000000ffffffff 0000000000000000 page dumped because: pagepool leak Modules linked in: ipgre gre mlx5ib mlx5core xtconntrack xtMASQUERADE nfconntracknetlink nfnetlink iptablenat nfnat xtaddrtype brnetfilter rpcrdma rdmaucm ibiser libiscsi scsitransportiscsi ibumad rdmacm ibipoib iwcm ibcm ibuverbs ibcore overlay zram zsmalloc fuse [last unloaded: mlx5core] CPU: 16 PID: 96 Comm: ksoftirqd/16 Not tainted 6.8.0-rc4+ #22 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Call Trace: <TASK> dumpstacklvl+0x36/0x50 badpage+0x70/0xf0 freeunrefpageprepare+0x27a/0x460 freeunrefpage+0x38/0x120 espssgunref.isra.0+0x15f/0x200 espoutputtail+0x66d/0x780 espxmit+0x2c5/0x360 validatexmitxfrm+0x313/0x370 ? validatexmitskb+0x1d/0x330 validatexmitskblist+0x4c/0x70 schdirectxmit+0x23e/0x350 _devqueuexmit+0x337/0xba0 ? nfhookslow+0x3f/0xd0 ipfinishoutput2+0x25e/0x580 iptunnelxmit+0x19b/0x240 iptunnelxmit+0x5fb/0xb60 ipgrexmit+0x14d/0x280 [ipgre] devhardstartxmit+0xc3/0x1c0 _devqueuexmit+0x208/0xba0 ? nfhookslow+0x3f/0xd0 ipfinishoutput2+0x1ca/0x580 ipsublistrcvfinish+0x32/0x40 ipsublistrcv+0x1b2/0x1f0 ? iprcvfinishcore.constprop.0+0x460/0x460 iplistrcv+0x103/0x130 _netifreceiveskblistcore+0x181/0x1e0 netifreceiveskblistinternal+0x1b3/0x2c0 napigroreceive+0xc8/0x200 grocellpoll+0x52/0x90 _napipoll+0x25/0x1a0 netrxaction+0x28e/0x300 _dosoftirq+0xc3/0x276 ? sortrange+0x20/0x20 runksoftirqd+0x1e/0x30 smpbootthreadfn+0xa6/0x130 kthread+0xcd/0x100 ? kthreadcompleteandexit+0x20/0x20 retfromfork+0x31/0x50 ? kthreadcompleteandexit+0x20/0x20 retfromforkasm+0x11/0x20 </TASK> The suggested fix is to introduce a new wrapper (skbpageunref) that covers page refcounting for pagepool pages as well.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-buildinfo-6.8.0-35-generic-64k", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-cloud-tools-6.8.0-35", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-cloud-tools-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-cloud-tools-common", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-doc", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-headers-6.8.0-35", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-headers-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-headers-6.8.0-35-generic-64k", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-6.8.0-35-generic-dbgsym", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-unsigned-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-unsigned-6.8.0-35-generic-64k", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-unsigned-6.8.0-35-generic-64k-dbgsym", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-image-unsigned-6.8.0-35-generic-dbgsym", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-lib-rust-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-libc-dev", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-6.8.0-35-generic-64k", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-extra-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-ipu6-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-modules-usbio-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-source-6.8.0", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-tools-6.8.0-35", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-tools-6.8.0-35-generic", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-tools-6.8.0-35-generic-64k", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-tools-common", "binary_version": "6.8.0-35.35" }, { "binary_name": "linux-tools-host", "binary_version": "6.8.0-35.35" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-aws-cloud-tools-6.8.0-1009", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-aws-headers-6.8.0-1009", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-aws-tools-6.8.0-1009", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-buildinfo-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-cloud-tools-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-headers-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-image-unsigned-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-image-unsigned-6.8.0-1009-aws-dbgsym", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-modules-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-modules-extra-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" }, { "binary_name": "linux-tools-6.8.0-1009-aws", "binary_version": "6.8.0-1009.9" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-azure-cloud-tools-6.8.0-1008", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-azure-headers-6.8.0-1008", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-azure-tools-6.8.0-1008", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-buildinfo-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-cloud-tools-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-headers-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-image-unsigned-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-image-unsigned-6.8.0-1008-azure-dbgsym", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-modules-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-modules-extra-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" }, { "binary_name": "linux-tools-6.8.0-1008-azure", "binary_version": "6.8.0-1008.8" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-gcp-headers-6.8.0-1008", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-gcp-tools-6.8.0-1008", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-headers-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-image-unsigned-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-image-unsigned-6.8.0-1008-gcp-dbgsym", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-modules-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-modules-extra-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" }, { "binary_name": "linux-tools-6.8.0-1008-gcp", "binary_version": "6.8.0-1008.9" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-gke-headers-6.8.0-1004", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-gke-tools-6.8.0-1004", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-headers-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-image-unsigned-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-image-unsigned-6.8.0-1004-gke-dbgsym", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-modules-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-modules-extra-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" }, { "binary_name": "linux-tools-6.8.0-1004-gke", "binary_version": "6.8.0-1004.7" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-headers-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-ibm-cloud-tools-common", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-ibm-headers-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-ibm-source-6.8.0", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-ibm-tools-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-ibm-dbgsym", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-extra-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-tools-6.8.0-1006-ibm", "binary_version": "6.8.0-1006.6" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-buildinfo-6.8.0-35-lowlatency-64k", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-cloud-tools-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-headers-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-headers-6.8.0-35-lowlatency-64k", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-unsigned-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-unsigned-6.8.0-35-lowlatency-64k", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-unsigned-6.8.0-35-lowlatency-64k-dbgsym", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-unsigned-6.8.0-35-lowlatency-dbgsym", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-cloud-tools-6.8.0-35", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-cloud-tools-common", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-headers-6.8.0-35", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-lib-rust-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-tools-6.8.0-35", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-tools-common", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-lowlatency-tools-host", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-modules-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-modules-6.8.0-35-lowlatency-64k", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-tools-6.8.0-35-lowlatency", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-tools-6.8.0-35-lowlatency-64k", "binary_version": "6.8.0-35.35.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-headers-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oem-dbgsym", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-ipu6-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-usbio-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-oem-6.8-headers-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-oem-6.8-tools-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-tools-6.8.0-1006-oem", "binary_version": "6.8.0-1006.6" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-buildinfo-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-headers-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-headers-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oracle-64k-dbgsym", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-image-unsigned-6.8.0-1006-oracle-dbgsym", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-extra-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-extra-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-modules-iwlwifi-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-oracle-headers-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-oracle-tools-6.8.0-1006", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-tools-6.8.0-1006-oracle", "binary_version": "6.8.0-1006.6" }, { "binary_name": "linux-tools-6.8.0-1006-oracle-64k", "binary_version": "6.8.0-1006.6" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-1005-raspi", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-headers-6.8.0-1005-raspi", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-image-6.8.0-1005-raspi", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-image-6.8.0-1005-raspi-dbgsym", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-modules-6.8.0-1005-raspi", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-raspi-headers-6.8.0-1005", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-raspi-tools-6.8.0-1005", "binary_version": "6.8.0-1005.5" }, { "binary_name": "linux-tools-6.8.0-1005-raspi", "binary_version": "6.8.0-1005.5" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-35-generic", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-headers-6.8.0-35-generic", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-6.8.0-35-generic", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-image-6.8.0-35-generic-dbgsym", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-modules-6.8.0-35-generic", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-riscv-headers-6.8.0-35", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-riscv-tools-6.8.0-35", "binary_version": "6.8.0-35.35.1" }, { "binary_name": "linux-tools-6.8.0-35-generic", "binary_version": "6.8.0-35.35.1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "linux-buildinfo-6.8.0-2004-raspi-realtime", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-headers-6.8.0-2004-raspi-realtime", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-image-6.8.0-2004-raspi-realtime", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-image-6.8.0-2004-raspi-realtime-dbgsym", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-modules-6.8.0-2004-raspi-realtime", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-raspi-realtime-headers-6.8.0-2004", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-raspi-realtime-tools-6.8.0-2004", "binary_version": "6.8.0-2004.4" }, { "binary_name": "linux-tools-6.8.0-2004-raspi-realtime", "binary_version": "6.8.0-2004.4" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "linux-buildinfo-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-cloud-tools-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-headers-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-image-unsigned-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-image-unsigned-6.8.1-1002-realtime-dbgsym", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-modules-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-modules-extra-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-modules-iwlwifi-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-realtime-cloud-tools-6.8.1-1002", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-realtime-headers-6.8.1-1002", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-realtime-tools-6.8.1-1002", "binary_version": "6.8.1-1002.2" }, { "binary_name": "linux-tools-6.8.1-1002-realtime", "binary_version": "6.8.1-1002.2" } ] }