Re: [PATCH] sunrpc: fix uninitialized xprt_create_args structure
"Anna Schumaker" <[email protected]>
| Newsgroups | gmane.linux.network,gmane.linux.nfs,gmane.linux.kernel.stable |
|---|---|
| Message-ID | <[email protected]> |
Hi Hongling, Thanks for the patch! On Tue, Jun 2, 2026, at 4:32 AM, Hongling Zeng wrote: > The xprt_create_args structure is allocated on the stack without > initialization in rpc_sysfs_xprt_switch_add_xprt_store(). While some > fields are manually populated, critical fields like srcaddr, bc_xps, > and flags contain uninitialized stack garbage. > > This can lead to: > 1. Kernel panic when xs_setup_xprt() dereferences garbage srcaddr > 2. Information leak if srcaddr points to sensitive stack data > 3. Unpredictable behavior if flags has random bits set I took a look through the transport setup function to see what they do when these fields are set to NULL, and it looks like thy do their best to choose a default value which might be different than the values set to the original transport that we are trying to clone. Can we instead set the missing fields in the xprt_create_args based on how the main xprt is configured? Thanks, Anna > > The fix is to zero-initialize the structure to ensure all unused > fields are NULL/0, preventing the transport setup code from acting > on garbage data. > > Cc: [email protected] > Signed-off-by: Hongling Zeng <[email protected]> > --- > net/sunrpc/sysfs.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/net/sunrpc/sysfs.c b/net/sunrpc/sysfs.c > index a90480f80154..0a99d0f1eb4c 100644 > --- a/net/sunrpc/sysfs.c > +++ b/net/sunrpc/sysfs.c > @@ -333,6 +333,7 @@ static ssize_t > rpc_sysfs_xprt_switch_add_xprt_store(struct kobject *kobj, > if (!xprt_switch) > return 0; > > + memset(&xprt_create_args, 0, sizeof(xprt_create_args)); > xprt = rpc_xprt_switch_get_main_xprt(xprt_switch); > if (!xprt) > goto out; > -- > 2.25.1