| From e456d6c0731704887d708fcb72791b742b7f6683 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 26 May 2026 21:33:19 +0200 |
| Subject: bonding: refuse to enslave CAN devices |
| |
| From: Oliver Hartkopp <socketcan@hartkopp.net> |
| |
| [ Upstream commit 8ba68464e4787b6a7ec938826e16124df20fd23d ] |
| |
| syzbot reported a kernel paging request crash in |
| can_rx_unregister() inside net/can/af_can.c. The crash occurs |
| because a virtual CAN device (vxcan) is being enslaved to a |
| bonding master. |
| |
| During the enslavement process, the bonding driver mutates |
| and modifies the network device states to fit an Ethernet-like |
| aggregation model. However, CAN devices operate on a completely |
| different Layer 2 architecture, relying on the CAN mid-layer |
| private data structure (can_ml_priv) instead of standard |
| Ethernet structures. Since bonding does not initialize or |
| maintain these CAN structures, subsequent operations on the |
| half-enslaved interface (such as closing associated sockets |
| via isotp_release) lead to a null-pointer dereference when |
| accessing the CAN receiver lists. |
| |
| Bonding CAN interfaces is architecturally invalid as CAN lacks |
| MAC addresses, ARP capabilities, and standard Ethernet |
| link-layer mechanisms. While generic loopback devices are |
| blocked globally in net/core/dev.c, virtual CAN devices |
| bypass this check because they do not carry the IFF_LOOPBACK |
| flag, despite acting as local software-loopbacks. |
| |
| Fix this by explicitly blocking network devices of type |
| ARPHRD_CAN from being enslaved at the very beginning of |
| bond_enslave(). This prevents illegal state mutations, |
| eliminates the resulting KASAN crashes, and avoids potential |
| memory leaks from incomplete socket cleanups. |
| |
| As the CAN support has been added a long time after bonding |
| the Fixes-tag points to the introduction of ARPHRD_CAN that |
| would have needed a specific handling in bonding_main.c. |
| |
| Fixes: cd05acfe65ed ("[CAN]: Allocate protocol numbers for PF_CAN") |
| Reported-by: syzbot+8ed98cbd0161632bce95@syzkaller.appspotmail.com |
| Closes: https://syzkaller.appspot.com/bug?extid=8ed98cbd0161632bce95 |
| Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net> |
| Acked-by: Jay Vosburgh <jv@jvosburgh.net> |
| Link: https://patch.msgid.link/20260526-bonding-candev-v1-1-ba1df400918a@hartkopp.net |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/net/bonding/bond_main.c | 6 ++++++ |
| 1 file changed, 6 insertions(+) |
| |
| diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c |
| index eb49ce486992de..d6a1e814878f28 100644 |
| --- a/drivers/net/bonding/bond_main.c |
| +++ b/drivers/net/bonding/bond_main.c |
| @@ -1892,6 +1892,12 @@ int bond_enslave(struct net_device *bond_dev, struct net_device *slave_dev, |
| struct sockaddr_storage ss; |
| int res = 0, i; |
| |
| + if (slave_dev->type == ARPHRD_CAN) { |
| + BOND_NL_ERR(bond_dev, extack, |
| + "CAN devices cannot be enslaved"); |
| + return -EPERM; |
| + } |
| + |
| if (slave_dev->flags & IFF_MASTER && |
| !netif_is_bond_master(slave_dev)) { |
| BOND_NL_ERR(bond_dev, extack, |
| -- |
| 2.53.0 |
| |