From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5CA5351A148; Wed, 30 Sep 2026 17:14:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788488; cv=none; b=f7RySCLb3VXYNYs2iM1MwpUTkneDmlSf1oz9VEH1vF0kco1laGQJS//kVUK2JmWTVneS/5VwzPJ0p3OS8va9FOqvDMwSyFmqi73LcK3Q5lfokL6G9vmx7hmDqIF2rMSiTCbdmRk3x89ghLVVTxMm/pOZO05OgXWg0uLHyrERLwE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788488; c=relaxed/simple; bh=FLmlz+kYI58bpzkU8Yv/Rc4sH/FqR+Y3rIrZznLj7Js=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bbC4VxxjiXbQDD/Yu3x01dMThWabPCFni0x1PjkKH0DcJS/Q7zZPhXxSQQxmMm6n2uZ/AVn3AMy/MdYXUbUEBbXtoLhxjxU4e3ufAxIJ85FDKYu6uMFkxOBdGdeyqGCvK9ay93zbLN69duqfS3IOl+MNJLVmydOv2AeIMNzDqEc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=P15qSyLU; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="P15qSyLU" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B54301F000FF; Wed, 30 Sep 2026 17:14:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788487; bh=EV7st1+SJgXWrmvCbsbNcrZOkEfx30jtfFTUxrWMojA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=P15qSyLU8DJ1xdZgtq4IiNdV3iXSU2QkOsuD0Y00rX/gvATTzosnz2JQA8Vb8wFj3 WIvOAdf5K1YyLEB4SK7IcX76bcP0H7gElzoB1+mXTIzfAR1Yb9N6SVneoIIe0L4y2z CX6yc5j4gnbuc6ub4HnC4ZLnAOFUcrv1ODpQ/CLY= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Eric Dumazet , Hangbin Liu , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.12 141/877] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Date: Wed, 30 Sep 2026 17:17:32 +0200 Message-ID: <20260930152417.770784391@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Eric Dumazet [ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ] In reset_per_cpu_data(), al is computed as: al = sizeof(struct net_dm_alert_msg); al += dm_hit_limit * sizeof(struct net_dm_drop_point); al += sizeof(struct nlattr); skb = genlmsg_new(al, GFP_KERNEL); ... nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg)); ... msg = nla_data(nla); memset(msg, 0, al); Because al includes sizeof(struct nlattr) (the 4-byte attribute header), genlmsg_new() allocates al bytes of tailroom starting at nla. However, msg points to nla_data(nla), which is located sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al) therefore writes al bytes starting from msg, exceeding the allocated buffer by sizeof(struct nlattr) (4 bytes) and corrupting skb_shared_info. Fix this by letting al represent only the payload length, allocating the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing al bytes from msg. Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message") Signed-off-by: Eric Dumazet Reviewed-by: Hangbin Liu Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin --- net/core/drop_monitor.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c index a9c604ef2c826..1ba281bef21e3 100644 --- a/net/core/drop_monitor.c +++ b/net/core/drop_monitor.c @@ -141,9 +141,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data) al = sizeof(struct net_dm_alert_msg); al += dm_hit_limit * sizeof(struct net_dm_drop_point); - al += sizeof(struct nlattr); - skb = genlmsg_new(al, GFP_KERNEL); + skb = genlmsg_new(nla_total_size(al), GFP_KERNEL); if (!skb) goto err; -- 2.53.0