Re: [PATCH net] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes

Xiang Mei <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel
Message-ID <CAPpSM+Ttdq=LASJ7cVQUuMs=5mrXxQnOQuweFLWhMoVnFrHfpQ@mail.gmail.com>
On Mon, Jul 20, 2026 at 5:25 PM Jakub Kicinski <[email protected]> wrote:
>
> On Sat,  4 Jul 2026 15:22:54 -0700 Xiang Mei wrote:
> > The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
> > attributes as NLA_BINARY with only a maximum length, so validate_nla()
> > accepts a payload shorter than the address. The GROUP consumer reads it
> > with nla_get_in_addr(), an unconditional 4-byte load, so a short
> > attribute over-reads up to 3 bytes of uninitialised slab data, which are
> > stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
> > kernel memory.
> >
> > Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects
> > any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is
> > always sent at full width.
>
> The netdev patch queue has overflown, if the patch is still needed
> you'll have to repost, sorry.

Thanks for the reminder. Sorry for the delayed reply. Just tested on
the latest netdev, and the patch is still needed.
I have resent with Reviewed-by: Ido Schimmel <[email protected]>.

The resent patch:
https://lore.kernel.org/netdev/[email protected]/T/#u

Xiang
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.