[PATCH net 1/1] net: use random salt for netdev name hash to prevent text base leak

From: Zhengchuan Liang

Date: Fri Oct 02 2026 - 02:54:18 EST


dev_name_hash() uses the network namespace pointer as the salt for the
network device name hash table. Unprivileged users can use SIOCGIFINDEX
to look up attacker-chosen nonexistent names. Timing these lookups
reveals which names share a bucket with an existing name, allowing the
salt to be recovered. For init_net, recovering the salt reveals the
kernel text base and defeats KASLR.

Use the per-network namespace random value from net_hash_mix() as the
salt instead. The value remains stable for the lifetime of the namespace.
Since all name insertions and lookups use dev_name_hash(), this only
changes bucket placement.

Fixes: 8387ff2577eb ("vfs: make the string hashes salt the hash")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <zcliangcn@xxxxxxxxx>
---
net/core/dev.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/net/core/dev.c b/net/core/dev.c
index 18dc88990510..f3eca7fa2481 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -98,6 +98,7 @@
#include <linux/bpf.h>
#include <linux/bpf_trace.h>
#include <net/net_namespace.h>
+#include <net/netns/hash.h>
#include <net/sock.h>
#include <net/busy_poll.h>
#include <linux/rtnetlink.h>
@@ -193,7 +194,10 @@ static inline void dev_base_seq_inc(struct net *net)

static inline struct hlist_head *dev_name_hash(struct net *net, const char *name)
{
- unsigned int hash = full_name_hash(net, name, strnlen(name, IFNAMSIZ));
+ unsigned long salt = net_hash_mix(net);
+ unsigned int hash;
+
+ hash = full_name_hash((void *)salt, name, strnlen(name, IFNAMSIZ));

return &net->dev_name_head[hash_32(hash, NETDEV_HASHBITS)];
}
--
2.25.1