* [PATCH net RESEND] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
@ 2026-08-12 21:53 Xiang Mei
2026-08-17 23:20 ` patchwork-bot+netdevbpf
0 siblings, 1 reply; 2+ messages in thread
From: Xiang Mei @ 2026-08-12 21:53 UTC (permalink / raw)
To: Jakub Kicinski, Ido Schimmel, Andrew Lunn, David S . Miller,
Eric Dumazet, Paolo Abeni, Roopa Prabhu
Cc: netdev, linux-kernel, Petr Machata, Andy Roulin, David Yang,
Kees Cook, Weiming Shi, Xiang Mei
The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
attributes as NLA_BINARY with only a maximum length, so validate_nla()
accepts a payload shorter than the address. The GROUP consumer reads it
with nla_get_in_addr(), an unconditional 4-byte load, so a short
attribute over-reads up to 3 bytes of uninitialised slab data, which are
stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
kernel memory.
Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects
any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is
always sent at full width.
Fixes: f9c4bb0b245c ("vxlan: vni filtering support on collect metadata device")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
---
resend: resend since netdev patch queue has overflown
https://lore.kernel.org/all/20260704222254.914567-1-xmei5%40asu.edu/
drivers/net/vxlan/vxlan_vnifilter.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_vnifilter.c b/drivers/net/vxlan/vxlan_vnifilter.c
index 3e76f4e21094..dd94085e0886 100644
--- a/drivers/net/vxlan/vxlan_vnifilter.c
+++ b/drivers/net/vxlan/vxlan_vnifilter.c
@@ -462,10 +462,8 @@ static int vxlan_vnifilter_dump(struct sk_buff *skb, struct netlink_callback *cb
static const struct nla_policy vni_filter_entry_policy[VXLAN_VNIFILTER_ENTRY_MAX + 1] = {
[VXLAN_VNIFILTER_ENTRY_START] = { .type = NLA_U32 },
[VXLAN_VNIFILTER_ENTRY_END] = { .type = NLA_U32 },
- [VXLAN_VNIFILTER_ENTRY_GROUP] = { .type = NLA_BINARY,
- .len = sizeof_field(struct iphdr, daddr) },
- [VXLAN_VNIFILTER_ENTRY_GROUP6] = { .type = NLA_BINARY,
- .len = sizeof(struct in6_addr) },
+ [VXLAN_VNIFILTER_ENTRY_GROUP] = NLA_POLICY_EXACT_LEN(sizeof_field(struct iphdr, daddr)),
+ [VXLAN_VNIFILTER_ENTRY_GROUP6] = NLA_POLICY_EXACT_LEN(sizeof(struct in6_addr)),
};
static const struct nla_policy vni_filter_policy[VXLAN_VNIFILTER_MAX + 1] = {
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH net RESEND] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
2026-08-12 21:53 [PATCH net RESEND] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes Xiang Mei
@ 2026-08-17 23:20 ` patchwork-bot+netdevbpf
0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-08-17 23:20 UTC (permalink / raw)
To: Xiang Mei
Cc: kuba, idosch, andrew+netdev, davem, edumazet, pabeni, roopa,
netdev, linux-kernel, petrm, aroulin, mmyangfl, kees, bestswngs
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Wed, 12 Aug 2026 14:53:41 -0700 you wrote:
> The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
> attributes as NLA_BINARY with only a maximum length, so validate_nla()
> accepts a payload shorter than the address. The GROUP consumer reads it
> with nla_get_in_addr(), an unconditional 4-byte load, so a short
> attribute over-reads up to 3 bytes of uninitialised slab data, which are
> stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
> kernel memory.
>
> [...]
Here is the summary with links:
- [net,RESEND] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
https://git.kernel.org/netdev/net/c/984f831dda31
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-17 23:20 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-12 21:53 [PATCH net RESEND] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes Xiang Mei
2026-08-17 23:20 ` patchwork-bot+netdevbpf
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.