Re: [PATCH net] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
Xiang Mei <[email protected]>
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAPpSM+Ttdq=LASJ7cVQUuMs=5mrXxQnOQuweFLWhMoVnFrHfpQ@mail.gmail.com> |
On Mon, Jul 20, 2026 at 5:25 PM Jakub Kicinski <[email protected]> wrote: > > On Sat, 4 Jul 2026 15:22:54 -0700 Xiang Mei wrote: > > The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address > > attributes as NLA_BINARY with only a maximum length, so validate_nla() > > accepts a payload shorter than the address. The GROUP consumer reads it > > with nla_get_in_addr(), an unconditional 4-byte load, so a short > > attribute over-reads up to 3 bytes of uninitialised slab data, which are > > stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing > > kernel memory. > > > > Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects > > any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is > > always sent at full width. > > The netdev patch queue has overflown, if the patch is still needed > you'll have to repost, sorry. Thanks for the reminder. Sorry for the delayed reply. Just tested on the latest netdev, and the patch is still needed. I have resent with Reviewed-by: Ido Schimmel <[email protected]>. The resent patch: https://lore.kernel.org/netdev/[email protected]/T/#u Xiang