Re: [PATCH 6.12] netconsole: avoid OOB reads, msg is not nul-terminated

Breno Leitao <[email protected]>
Newsgroups gmane.linux.kernel.stable,gmane.linux.network,gmane.linux.kernel
Message-ID <[email protected]>
On Mon, Aug 03, 2026 at 08:41:29PM +0200, Markus Boehme wrote:
> From: Jakub Kicinski <[email protected]>
> 
> [ Upstream commit 82aec772fca2223bc5774bd9af486fd95766e578 ]
> 
> msg passed to netconsole from the console subsystem is not guaranteed
> to be nul-terminated. Before recent
> commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure")
> the message would be placed in printk_shared_pbufs, a static global
> buffer, so KASAN had harder time catching OOB accesses. Now we see:
> 
>     printk: console [netcon_ext0] enabled
>     BUG: KASAN: slab-out-of-bounds in string+0x1f7/0x240
>     Read of size 1 at addr ffff88813b6d4c00 by task pr/netcon_ext0/594
> 
>     CPU: 65 UID: 0 PID: 594 Comm: pr/netcon_ext0 Not tainted 6.19.0-11754-g4246fd6547c9
>     Call Trace:
>      kasan_report+0xe4/0x120
>      string+0x1f7/0x240
>      vsnprintf+0x655/0xba0
>      scnprintf+0xba/0x120
>      netconsole_write+0x3fe/0xa10
>      nbcon_emit_next_record+0x46e/0x860
>      nbcon_kthread_func+0x623/0x750
> 
>     Allocated by task 1:
>      nbcon_alloc+0x1ea/0x450
>      register_console+0x26b/0xe10
>      init_netconsole+0xbb0/0xda0
> 
>     The buggy address belongs to the object at ffff88813b6d4000
>                 which belongs to the cache kmalloc-4k of size 4096
>     The buggy address is located 0 bytes to the right of
>                 allocated 3072-byte region [ffff88813b6d4000, ffff88813b6d4c00)
> 
> Fixes: c62c0a17f9b7 ("netconsole: Append kernel version to message")
> Signed-off-by: Jakub Kicinski <[email protected]>
> Reviewed-by: Simon Horman <[email protected]>
> Link: https://patch.msgid.link/[email protected]
> Signed-off-by: Paolo Abeni <[email protected]>

Acked-by: Breno Leitao <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.