mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload before overwriting it with skb_copy_bits(). skb_put() reserves nla_total_size(payload_len), i.e. the header plus the NLA_ALIGN() padding, but only payload_len bytes are copied in. When payload_len is not a multiple of 4 the 1-3 padding bytes are never initialized and are leaked to user space inside the netlink message. KMSAN confirms the leak for the software path when the packet payload length is not 4-byte aligned: BUG: KMSAN: kernel-infoleak in _copy_to_iter _copy_to_iter __skb_datagram_iter skb_copy_datagram_iter netlink_recvmsg sock_recvmsg __sys_recvfrom Uninit was created at: kmem_cache_alloc_node_noprof __alloc_skb net_dm_packet_work Bytes 173-175 of 176 are uninitialized Use __nla_reserve(), which sets up the attribute header and zeroes the padding, instead of open coding the attribute construction. Fixes:ca30707dee("drop_monitor: Add packet alert mode") Fixes:5e58109b1e("drop_monitor: Add support for packet alert mode for hardware drops") Suggested-by: Eric Dumazet <edumazet@google.com> Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr> Link: https://patch.msgid.link/20260722122817.5548-1-yhlee@isslab.korea.ac.kr Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
1d4da823b7
commit
5e9c8baee0
|
|
@ -671,9 +671,7 @@ static int net_dm_packet_report_fill(struct sk_buff *msg, struct sk_buff *skb,
|
|||
if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
|
||||
goto nla_put_failure;
|
||||
|
||||
attr = skb_put(msg, nla_total_size(payload_len));
|
||||
attr->nla_type = NET_DM_ATTR_PAYLOAD;
|
||||
attr->nla_len = nla_attr_size(payload_len);
|
||||
attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
|
||||
if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
|
||||
goto nla_put_failure;
|
||||
|
||||
|
|
@ -831,9 +829,7 @@ static int net_dm_hw_packet_report_fill(struct sk_buff *msg,
|
|||
if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
|
||||
goto nla_put_failure;
|
||||
|
||||
attr = skb_put(msg, nla_total_size(payload_len));
|
||||
attr->nla_type = NET_DM_ATTR_PAYLOAD;
|
||||
attr->nla_len = nla_attr_size(payload_len);
|
||||
attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
|
||||
if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
|
||||
goto nla_put_failure;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user