Re: [PATCH] sunrpc: fix uninitialized xprt_create_args structure
Jeff Layton <[email protected]>
| Newsgroups | gmane.linux.kernel.stable,gmane.linux.nfs,gmane.linux.network |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 2026-06-02 at 16:32 +0800, Hongling Zeng wrote: > The xprt_create_args structure is allocated on the stack without > initialization in rpc_sysfs_xprt_switch_add_xprt_store(). While some > fields are manually populated, critical fields like srcaddr, bc_xps, > and flags contain uninitialized stack garbage. > > This can lead to: > 1. Kernel panic when xs_setup_xprt() dereferences garbage srcaddr > 2. Information leak if srcaddr points to sensitive stack data > 3. Unpredictable behavior if flags has random bits set > > The fix is to zero-initialize the structure to ensure all unused > fields are NULL/0, preventing the transport setup code from acting > on garbage data. > > Cc: [email protected] > Signed-off-by: Hongling Zeng <[email protected]> > --- > net/sunrpc/sysfs.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/net/sunrpc/sysfs.c b/net/sunrpc/sysfs.c > index a90480f80154..0a99d0f1eb4c 100644 > --- a/net/sunrpc/sysfs.c > +++ b/net/sunrpc/sysfs.c > @@ -333,6 +333,7 @@ static ssize_t rpc_sysfs_xprt_switch_add_xprt_store(struct kobject *kobj, > if (!xprt_switch) > return 0; > > + memset(&xprt_create_args, 0, sizeof(xprt_create_args)); > xprt = rpc_xprt_switch_get_main_xprt(xprt_switch); > if (!xprt) > goto out; Good catch. You could also just use an initializer here at declaration. A'la: struct xprt_create xprt_create_args = {}; ...but this works too, of course. Reviewed-by: Jeff Layton <[email protected]>