Re: [PATCH] sunrpc: fix uninitialized xprt_create_args structure

"Anna Schumaker" <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.nfs,gmane.linux.kernel.stable
Message-ID <[email protected]>
Hi Hongling,

Thanks for the patch!

On Tue, Jun 2, 2026, at 4:32 AM, Hongling Zeng wrote:
> The xprt_create_args structure is allocated on the stack without
> initialization in rpc_sysfs_xprt_switch_add_xprt_store(). While some
> fields are manually populated, critical fields like srcaddr, bc_xps,
> and flags contain uninitialized stack garbage.
>
> This can lead to:
> 1. Kernel panic when xs_setup_xprt() dereferences garbage srcaddr
> 2. Information leak if srcaddr points to sensitive stack data
> 3. Unpredictable behavior if flags has random bits set

I took a look through the transport setup function to see what they
do when these fields are set to NULL, and it looks like thy do their
best to choose a default value which might be different than the
values set to the original transport that we are trying to clone.

Can we instead set the missing fields in the xprt_create_args based
on how the main xprt is configured?

Thanks,
Anna

>
> The fix is to zero-initialize the structure to ensure all unused
> fields are NULL/0, preventing the transport setup code from acting
> on garbage data.
>
> Cc: [email protected]
> Signed-off-by: Hongling Zeng <[email protected]>
> ---
>  net/sunrpc/sysfs.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/net/sunrpc/sysfs.c b/net/sunrpc/sysfs.c
> index a90480f80154..0a99d0f1eb4c 100644
> --- a/net/sunrpc/sysfs.c
> +++ b/net/sunrpc/sysfs.c
> @@ -333,6 +333,7 @@ static ssize_t 
> rpc_sysfs_xprt_switch_add_xprt_store(struct kobject *kobj,
>  	if (!xprt_switch)
>  		return 0;
> 
> +	memset(&xprt_create_args, 0, sizeof(xprt_create_args));
>  	xprt = rpc_xprt_switch_get_main_xprt(xprt_switch);
>  	if (!xprt)
>  		goto out;
> -- 
> 2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.